Skip to content

HashiCorp Vault Improper Privilege Management

Critical severity GitHub Reviewed Published Jan 30, 2024 to the GitHub Advisory Database • Updated Jan 30, 2024

Package

gomod github.com/hashicorp/vault/vault (Go)

Affected versions

>= 0.11.0, < 1.3.4

Patched versions

1.3.4

Description

HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.

References

Published to the GitHub Advisory Database Jan 30, 2024
Reviewed Jan 30, 2024
Last updated Jan 30, 2024

Severity

Critical
9.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CVE ID

CVE-2020-10661

GHSA ID

GHSA-j6vv-vv26-rh7c

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.