HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2145 HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
Github GHSA Github GHSA GHSA-362v-wg5p-64w2 Incorrect Privilege Assignment in HashiCorp Vault
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:30:38.162Z

Reserved: 2021-10-11T00:00:00

Link: CVE-2021-42135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-11T03:15:06.760

Modified: 2024-11-21T06:27:20.020

Link: CVE-2021-42135

cve-icon Redhat

Severity : Important

Publid Date: 2021-10-11T00:00:00Z

Links: CVE-2021-42135 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses