HIGH 8.1 Go
Incorrect Privilege Assignment in HashiCorp Vault
GHSA-362v-wg5p-64w2 · BIT-vault-2021-42135 · CVE-2021-42135 · GO-2022-0578
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-42135
- WEB https://discuss.hashicorp.com/t/hcsec-2021-28-vaults-google-cloud-secrets-engine-policies-with-globs-may-provide-additional-privileges-in-vault-1-8-0-onwards
- PACKAGE https://github.com/hashicorp/vault
- WEB https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#180
Ready to move
Start Securing
Free, no credit card | First findings in minutes