SB2021100818 - Incorrect permission assignment in HashiCorp Vault
Published: October 8, 2021 Updated: August 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect permission assignment for critical resource (CVE-ID: CVE-2021-41802)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to incorrect permissions assignment. A remote user with write permission to an entity alias ID can share a mount accessor with another user to acquire this other user’s policies by merging their identities.
Remediation
Install update from vendor's website.