CVE-2021-41802: Medium severity HashiCorp Vault vulnerability
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Vault and Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.7.5 - Upgrade
Upgrade
HashiCorp Vault and Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.8.4
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-41802.
What is the affected software?
The affected software is HashiCorp Vault and Vault Enterprise versions up to 1.7.4 and 1.8.3.
What is the severity of CVE-2021-41802?
The severity of CVE-2021-41802 is medium with a severity score of 5.4.
How does CVE-2021-41802 impact users?
CVE-2021-41802 allows a user with write permission to acquire another user's policies by merging their identities.
How can I fix CVE-2021-41802?
To fix CVE-2021-41802, update to HashiCorp Vault and Vault Enterprise versions 1.7.5 and 1.8.4.