First published: Thu Sep 28 2023(Updated: )
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
Credit: security@hashicorp.com security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=0.10.0<1.13.0 | |
HashiCorp Vault | >=0.10.0<1.13.0 | |
>=0.10.0<1.13.0 | ||
>=0.10.0<1.13.0 | ||
go/github.com/hashicorp/vault | <1.13.0 | 1.13.0 |
redhat/vault | <1.13.0 | 1.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-5077.
The title of this vulnerability is 'The Vault and Vault Enterprise ( Vault ) Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets.'
The severity level of CVE-2023-5077 is high with a value of 7.6.
To fix this vulnerability, update Vault to version 1.13.0 or higher.
You can find more information about CVE-2023-5077 on the NIST National Vulnerability Database, the HashiCorp forum, and the GitHub security advisory.