GHSA-pfmw-vj74-ph8g
Dashboard / Vulnerabilities / GHSA-pfmw-vj74-ph8g
GHSA-pfmw-vj74-ph8g
Summary: HashiCorp Vault Incorrect Permission Assignment for Critical Resource
Details: HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-43998, https://discuss.hashicorp.com/t/hcsec-2021-30-vaults-templated-acl-policies-matched-first-created-alias-per-entity-and-auth-backend/32132, https://github.com/hashicorp/vault, https://security.gentoo.org/glsa/202207-01
Affected packages
Package
Name: github.com/hashicorp/vault
Purl: pkg:golang/github.com/hashicorp/vault
Affected ranges
Type: SEMVER
Events:
