Improper access control in Vault Enterprise and Vault - CVE-2023-24999
Published: March 11, 2023
Vulnerability identifier: #VU73246
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24999
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service attack.
The vulnerability exists due to the way the application handles authentication based on Approle SecretID. A remote user with access to the "/auth/approle/role/:role_name/secret-id-accessor/destroy" endpoint can destroy the secret ID of any other role by providing the secret ID accessor and disable access to Vault for other users.Affected software
Vault Enterprise
Vault
IBM Cloud Pak for Watson AIOps
Cloud Pak for Network Automation
Storage Fusion Data Foundation
OpenShift Data Foundation (formerly OpenShift Container Storage)
Vault
IBM Cloud Pak for Watson AIOps
Cloud Pak for Network Automation
Storage Fusion Data Foundation
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2023-24999
Install updates from vendor's website.
Vault Enterprise - addressed in versions 1.10.11, 1.11.8, 1.12.4, 1.13.0
Vault - addressed in versions 1.10.11, 1.11.8, 1.12.4, 1.13.0
Cloud Pak for Network Automation - update to 2.4.7
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Storage Fusion Data Foundation - update to 4.13
Vault - addressed in versions 1.10.11, 1.11.8, 1.12.4, 1.13.0
Cloud Pak for Network Automation - update to 2.4.7
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Storage Fusion Data Foundation - update to 4.13