CVE-2023-3775: Vault Enterprise's Sentinel RGP Policies Allowed For Cross-Namespace Denial of Service
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-3775.
What is the severity of CVE-2023-3775?
The severity of CVE-2023-3775 is medium with a CVSS score of 4.2.
Which version of Vault Enterprise is affected by CVE-2023-3775?
Vault Enterprise versions between 0.11.0 and 1.13.8, as well as versions between 1.14.0 and 1.14.4, are affected by CVE-2023-3775.
How can I fix CVE-2023-3775?
To fix CVE-2023-3775, update your Vault Enterprise installation to version 1.15.0, 1.14.4, or 1.13.8.
Where can I find more information about CVE-2023-3775?
You can find more information about CVE-2023-3775 in the following reference: [link](https://discuss.hashicorp.com/t/hcsec-2023-29-vault-enterprise-s-sentinel-rgp-policies-allowed-for-cross-namespace-denial-of-service/58653)