Описание
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Affected | ||
cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-acmesolver-rhel9 | Affected | ||
cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Affected | ||
external secrets operator for Red Hat OpenShift - Tech Preview | external-secrets-operator/external-secrets-operator-rhel9 | Affected | ||
Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Affected | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Affected | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Affected | ||
Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Affected | ||
Red Hat Trusted Artifact Signer | rhtas/client-server-rhel9 | Affected | ||
Red Hat Trusted Artifact Signer | rhtas/fulcio-rhel9 | Affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2386006github.com/hashicorp/vault: Vault Identity Token Privilege Escalation
7.2 High
CVSS3
Связанные уязвимости
CVSS3: 7.2
nvd
5 дней назад
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
CVSS3: 7.2
github
5 дней назад
Hashicorp Vault has Privilege Escalation Vulnerability
7.2 High
CVSS3