Description
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2145 | HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials. |
Github GHSA |
GHSA-362v-wg5p-64w2 | Incorrect Privilege Assignment in HashiCorp Vault |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:30:38.162Z
Reserved: 2021-10-11T00:00:00.000Z
Link: CVE-2021-42135
No data.
Status : Modified
Published: 2021-10-11T03:15:06.760
Modified: 2024-11-21T06:27:20.020
Link: CVE-2021-42135
OpenCVE Enrichment
No data.
EUVD
Github GHSA