HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published: 2023-10-27T21:06:38.680Z

Updated: 2024-09-09T17:58:26.595Z

Reserved: 2023-10-27T19:52:44.844Z

Link: CVE-2023-5834

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:24.694Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-27T22:15:09.163

Modified: 2023-11-13T14:34:59.287

Link: CVE-2023-5834

cve-icon Redhat

No data.