The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2463 | The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0. |
Github GHSA |
GHSA-86c6-3g63-5w64 | Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| Vendors & Products |
Redhat openshift
|
Thu, 26 Sep 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 |
Mon, 23 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-09-26T21:57:22.469Z
Reserved: 2023-09-19T20:49:08.136Z
Link: CVE-2023-5077
Updated: 2024-08-02T07:44:53.829Z
Status : Modified
Published: 2023-09-29T00:15:12.693
Modified: 2024-11-21T08:41:01.217
Link: CVE-2023-5077
OpenCVE Enrichment
No data.
EUVD
Github GHSA