HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
CVE Status: Modified
Attribute | Value |
---|---|
Attack Complexity | LOW |
Attack Vector | ADJACENT_NETWORK |
Availability Impact | NONE |
Base Score | 2.9 |
Base Severity | LOW |
Confidentiality Impact | LOW |
Integrity Impact | NONE |
Privileges Required | HIGH |
Scope | CHANGED |
User Interaction | REQUIRED |
Vector String | CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N |
Exploitability Score | 1.2 |
Impact Score | 1.4 |
Source | [email protected] |
Type | Secondary |