VDB
Sign up
LOW2.9

GHSA-qv95-g3gm-x542

Hashicorp Vault Privilege Escalation Vulnerability

Quick fix

GHSA-qv95-g3gm-x542 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.7.5

Details

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0Fixed in: 1.7.5
Fixgo get github.com/hashicorp/vault@v1.7.5
Go/github.com/hashicorp/vault
Introduced in: 1.8.0Fixed in: 1.8.4
Fixgo get github.com/hashicorp/vault@v1.8.4

References