Permissions, Privileges, and Access Controls in Vault Enterprise and Vault - CVE-2021-43998
Published: August 4, 2022
Vulnerability identifier: #VU66115
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43998
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to templated ACL policies always match the first-created entity alias
if multiple entity aliases exist for a specified entity and mount
combination. A remote user can trigger incorrect policy enforcement.
Affected software
Vault Enterprise
Vault
Gentoo Linux
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
Vault
Gentoo Linux
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2021-43998
Install updates from vendor's website.
Vault Enterprise - addressed in versions 1.7.6, 1.8.5
Vault - addressed in versions 1.7.6, 1.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Vault - addressed in versions 1.7.6, 1.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0