First published: Fri Jun 09 2023(Updated: )
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, <a href="https://access.redhat.com/security/cve/CVE-2023-2121">CVE-2023-2121</a>, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11. <a href="https://discuss.hashicorp.com/t/hcsec-2023-17-vault-s-kv-diff-viewer-allowed-html-injection/54814">https://discuss.hashicorp.com/t/hcsec-2023-17-vault-s-kv-diff-viewer-allowed-html-injection/54814</a>
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | <1.11.11 | |
HashiCorp Vault | <1.11.11 | |
HashiCorp Vault | >=1.12.0<1.12.7 | |
HashiCorp Vault | >=1.12.0<1.12.7 | |
HashiCorp Vault | >=1.13.0<1.13.3 | |
HashiCorp Vault | >=1.13.0<1.13.3 | |
go/github.com/hashicorp/vault | >=1.13.0<1.13.3 | 1.13.3 |
go/github.com/hashicorp/vault | >=1.12.0<1.12.7 | 1.12.7 |
go/github.com/hashicorp/vault | <1.11.11 | 1.11.11 |
redhat/vault | <1.14.0 | 1.14.0 |
redhat/vault | <1.13.3 | 1.13.3 |
redhat/vault | <1.12.7 | 1.12.7 |
redhat/vault | <1.11.11 | 1.11.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-2121.
The severity of CVE-2023-2121 is medium with a severity value of 5.4.
Versions up to and including 1.11.11, 1.12.0 up to and including 1.12.7, and 1.13.0 up to and including 1.13.3 of HashiCorp Vault are affected by CVE-2023-2121.
CVE-2023-2121 can be fixed by upgrading to Vault 1.14.0, 1.13.3, 1.12.7, or 1.11.11.
Yes, you can find more information about CVE-2023-2121 at the following link: [Link](https://discuss.hashicorp.com/t/hcsec-2023-17-vault-s-kv-diff-viewer-allowed-html-injection/54814)