LOW2.9
GHSA-qv95-g3gm-x542
Hashicorp Vault Privilege Escalation Vulnerability
Quick fix
GHSA-qv95-g3gm-x542 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.7.5Details
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0Fixed in: 1.7.5Fix
go get github.com/hashicorp/vault@v1.7.5Go/github.com/hashicorp/vault
Introduced in:
1.8.0Fixed in: 1.8.4Fix
go get github.com/hashicorp/vault@v1.8.4