Vault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets
CVE-2023-5077
7.5HIGH
What is CVE-2023-5077?
The Google Cloud secrets engine in HashiCorp Vault exhibits a vulnerability where existing IAM Conditions are removed when creating or updating rolesets. This flaw affects the way Vault interacts with Google Cloud IAM, potentially compromising the intended access controls and security configurations. Users are recommended to upgrade to Vault version 1.13.0 or later to mitigate this issue and ensure the preservation of IAM Conditions during roleset management.
Affected Version(s)
Vault 64 bit 0.10.0 < 1.13.0
Vault Enterprise 64 bit 0.10.0 < 1.13.0