GHSA-jg74-mwgw-v6x3
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Quick fix
GHSA-jg74-mwgw-v6x3 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.17.6Details
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.7.7Fixed in: 1.17.6go get github.com/hashicorp/vault@v1.17.60.1.0No fixed version published yet for github.com/openbao/openbao (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 0.0.0-20241003222810-d5b4e9224698go get github.com/openbao/openbao@v0.0.0-20241003222810-d5b4e9224698References
- https://nvd.nist.gov/vuln/detail/CVE-2024-7594[ADVISORY]
- https://github.com/openbao/openbao/pull/561[WEB]
- https://github.com/openbao/openbao/commit/d5b4e922469830ac335b21dc0e8f9878c501a884[WEB]
- https://discuss.hashicorp.com/t/hcsec-2024-20-vault-ssh-secrets-engine-configuration-did-not-restrict-valid-principals-by-default/70251[WEB]
- https://github.com/hashicorp/vault[PACKAGE]
- https://openbao.org/docs/release-notes/2-0-0/#202[WEB]
- https://pkg.go.dev/vuln/GO-2024-3162[WEB]
- https://security.netapp.com/advisory/ntap-20250110-0007[WEB]