Improper Privilege Management in Vault Enterprise and Vault - CVE-2023-5077
Published: September 29, 2023
Vulnerability identifier: #VU81266
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5077
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass certain security restrictions.
The vulnerability exists in Google Cloud secrets engine due to incorrect preservation of existing Google Cloud IAM Conditions upon creating or updating rolesets. A remote user can gain unauthorized access to the application.
Affected software
Vault Enterprise
Vault
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Vault
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
How to mitigate CVE-2023-5077
Install updates from vendor's website.
Vault Enterprise - update to 1.13.0
Vault - update to 1.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Red Hat OpenShift Container Platform - update to 4.17.0
Vault - update to 1.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Red Hat OpenShift Container Platform - update to 4.17.0