Vault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy Operation
CVE-2023-24999
8.1HIGH
Summary
A security issue in HashiCorp Vault's approle authorization method allows any authenticated user with the ability to access the approle destroy endpoint to eliminate the secret ID of any other role. This is accomplished by passing the secret ID accessor, leading to potential unauthorized access and manipulation of sensitive credentials. It is crucial for users of affected Vault versions to upgrade to the patched releases to mitigate this risk.
Affected Version(s)
Vault Enterprise Windows 1.12.0 < 1.12.4
Vault Enterprise Windows 1.11.0 < 1.11.8
Vault Enterprise Windows 0 < 1.10.11
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved