Description


HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

Related CPE's


a

hashicorp

vault

4

Weaknesses



CWE-732

CVSS impact metrics


CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

2.9 · Low

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-08T15:15:07.853Z

4 years ago

Last modified

2024-11-21T05:26:47.460Z

1 year ago