Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-9180

Опубликовано: 10 окт. 2024
Источник: redhat
CVSS3: 7.2

Описание

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

A flaw was found in HashiCorp Vault. This vulnerability allows a privileged Vault operator with write permissions to the root namespace's identity endpoint to escalate their privileges to Vault’s root policy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Affected
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorAffected
Red Hat Openshift Container Storage 4ocs4/ocs-must-gather-rhel8Affected
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorAffected
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorAffected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/mcg-cli-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/odf-cli-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2317923hashicorp/vault: Vault Operators in Root Namespace May Elevate Their Privileges

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
9 месяцев назад

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

CVSS3: 7.2
redos
8 месяцев назад

Уязвимость vault

CVSS3: 7.2
github
9 месяцев назад

Vault Community Edition privilege escalation vulnerability

CVSS3: 7.2
fstec
9 месяцев назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с неправильным назначением привилегий, позволяющая нарушителю повысить свои привилегии

suse-cvrf
8 месяцев назад

Security update for govulncheck-vulndb

7.2 High

CVSS3