HIGH 8.1 Go

Incorrect Privilege Assignment in HashiCorp Vault

GHSA-362v-wg5p-64w2 · BIT-vault-2021-42135 · CVE-2021-42135 · GO-2022-0578

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.

Ready to move

Start Securing

Free, no credit card | First findings in minutes