MEDIUM4.3
GHSA-gq98-53rq-qr5h
Hashicorp Vault vulnerable to Cross-site Scripting
Quick fix
GHSA-gq98-53rq-qr5h — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.11.11Details
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0Fixed in: 1.11.11Fix
go get github.com/hashicorp/vault@v1.11.11Go/github.com/hashicorp/vault
Introduced in:
1.12.0Fixed in: 1.12.7Fix
go get github.com/hashicorp/vault@v1.12.7Go/github.com/hashicorp/vault
Introduced in:
1.13.0Fixed in: 1.13.3Fix
go get github.com/hashicorp/vault@v1.13.3