CVE-2021-43998: Medium severity HashiCorp Vault vulnerability
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43998?
The severity of CVE-2021-43998 is rated as medium, indicating potential policy enforcement issues that require attention.
How do I fix CVE-2021-43998?
To fix CVE-2021-43998, upgrade HashiCorp Vault to version 1.7.6 or later, or 1.8.5 and above.
What versions of HashiCorp Vault are affected by CVE-2021-43998?
CVE-2021-43998 affects HashiCorp Vault versions from 0.11.0 to 1.7.5 and specifically version 1.8.4.
What is the impact of CVE-2021-43998?
The impact of CVE-2021-43998 may lead to incorrect policy enforcement due to template ACL policies incorrectly matching entity aliases.
Is there a workaround for CVE-2021-43998?
There is no official workaround for CVE-2021-43998, so upgrading to a patched version is recommended.