VDB
Sign up
MEDIUM4.3

GHSA-gq98-53rq-qr5h

Hashicorp Vault vulnerable to Cross-site Scripting

Quick fix

GHSA-gq98-53rq-qr5h — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.11.11

Details

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0Fixed in: 1.11.11
Fixgo get github.com/hashicorp/vault@v1.11.11
Go/github.com/hashicorp/vault
Introduced in: 1.12.0Fixed in: 1.12.7
Fixgo get github.com/hashicorp/vault@v1.12.7
Go/github.com/hashicorp/vault
Introduced in: 1.13.0Fixed in: 1.13.3
Fixgo get github.com/hashicorp/vault@v1.13.3

References