Описание
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.
A flaw was found in HashiCorp Vault. This vulnerability allows a privileged Vault operator with write permissions to the root namespace's identity endpoint to escalate their privileges to Vault’s root policy.
A misconfiguration in Vault allows a privileged operator (someone with write permissions on the root namespace’s identity endpoint) to elevate privileges—either their own or another user’s—to the root policy level, effectively giving full administrative control.
Меры по смягчению последствий
This CVE can be mitigated by the following:
- Upgrade to a version of Vault that has the fix.
- Restrict write access to the root namespace’s identity endpoint.
- Implement least privilege policies (e.g., via Sentinel) that limit what root-namespace operators can do.
- Monitor audit logs: check for any “identity_policy” entries containing “root” to detect suspicious privilege escalations.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Affected | ||
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Affected | ||
| Red Hat Openshift Container Storage 4 | ocs4/ocs-must-gather-rhel8 | Affected | ||
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Affected | ||
| Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.2 High
CVSS3
Связанные уязвимости
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.
Vault Community Edition privilege escalation vulnerability
Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с неправильным назначением привилегий, позволяющая нарушителю повысить свои привилегии
EPSS
7.2 High
CVSS3