Vault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy Operation

CVE-2023-24999
8.1HIGH

Key Information

Vendor
HashiCorp
Status
Vault
Vault Enterprise
Vendor
CVE Published:
11 March 2023

Summary

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.

Affected Version(s)

Vault < 1.12.4

Vault < 1.11.8

Vault < 1.10.11

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.