Lucene search

K
osvGoogleOSV:GHSA-PFMW-VJ74-PH8G
HistoryDec 02, 2021 - 5:48 p.m.

HashiCorp Vault Incorrect Permission Assignment for Critical Resource

2021-12-0217:48:30
Google
osv.dev
7

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.4%

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.4%