VDB
Sign up
HIGH7.5

GHSA-jg74-mwgw-v6x3

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Quick fix

GHSA-jg74-mwgw-v6x3 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.17.6

Details

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 1.7.7Fixed in: 1.17.6
Fixgo get github.com/hashicorp/vault@v1.17.6
Go/github.com/openbao/openbao
Introduced in: 0.1.0

No fixed version published yet for github.com/openbao/openbao (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/openbao/openbao
Introduced in: 0Fixed in: 0.0.0-20241003222810-d5b4e9224698
Fixgo get github.com/openbao/openbao@v0.0.0-20241003222810-d5b4e9224698

References