Description
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
Related CPE's
a
hashicorp
vault
4
References
https://security.gentoo.org/glsa/202207-01
Third Party Advisory
https://security.gentoo.org/glsa/202207-01
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
2.9 · Low
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-08T15:15:07.853Z
4 years agoLast modified
2024-11-21T05:26:47.460Z
1 year ago