Improper access control in Vault Enterprise and Vault - CVE-2023-24999

 

Improper access control in Vault Enterprise and Vault - CVE-2023-24999

Published: March 11, 2023


Vulnerability identifier: #VU73246
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24999
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service attack.

The vulnerability exists due to the way the application handles authentication based on Approle SecretID. A remote user with access to the "/auth/approle/role/:role_name/secret-id-accessor/destroy" endpoint can destroy the secret ID of any other role by providing the secret ID accessor and disable access to Vault for other users.

Affected software

Vault Enterprise
Vault
IBM Cloud Pak for Watson AIOps
Cloud Pak for Network Automation
Storage Fusion Data Foundation
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2023-24999

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.10.11, 1.11.8, 1.12.4, 1.13.0
Vault - addressed in versions 1.10.11, 1.11.8, 1.12.4, 1.13.0
Cloud Pak for Network Automation - update to 2.4.7
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Storage Fusion Data Foundation - update to 4.13

External References

Related Security Bulletins