Lucene search

K
osvGoogleOSV:CVE-2021-41802
HistoryOct 08, 2021 - 5:15 p.m.

CVE-2021-41802

2021-10-0817:15:07
Google
osv.dev
6

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

CPENameOperatorVersion
vaulteq1.8.1
vaulteq1.8.0
vaulteq1.8.3
vaulteq1.8.2

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%