First published: Thu Sep 28 2023(Updated: )
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=0.11.0<1.13.8 | |
HashiCorp Vault | >=1.14.0<1.14.4 | |
redhat/Vault Enterprise | <1.15.0 | 1.15.0 |
redhat/and | <1.13.8 | 1.13.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-3775.
The severity of CVE-2023-3775 is medium with a CVSS score of 4.2.
Vault Enterprise versions between 0.11.0 and 1.13.8, as well as versions between 1.14.0 and 1.14.4, are affected by CVE-2023-3775.
To fix CVE-2023-3775, update your Vault Enterprise installation to version 1.15.0, 1.14.4, or 1.13.8.
You can find more information about CVE-2023-3775 in the following reference: [link](https://discuss.hashicorp.com/t/hcsec-2023-29-vault-enterprise-s-sentinel-rgp-policies-allowed-for-cross-namespace-denial-of-service/58653)