Описание
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
A flaw was found in Vault. When a Vault authentication mount is configured to pass through the "Authorization" header, and this header is used for authentication, Vault incorrectly forwards the sensitive Vault token to the authentication plugin backend. This can lead to the disclosure of authentication tokens to potentially untrusted or compromised backend plugins, enabling unauthorized access or further system compromise.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-installer-rhel9 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer-rhel9 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | cephcsi-rhel8 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | cephcsi-rhel9 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | mcg-cli-rhel9 | Affected | ||
| Red Hat Openshift Data Foundation 4 | mcg-rhel8-operator | Affected | ||
| Red Hat Openshift Data Foundation 4 | mcg-rhel9-operator | Affected | ||
| Red Hat Openshift Data Foundation 4 | ocs4/cephcsi-rhel8 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel8 | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
7.5 High
CVSS3