CVE-2023-24999

Name
CVE-2023-24999
Description
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://discuss.hashicorp.com/t/hcsec-2023-07-vault-fails-to-verify-if-approle-secretid-belongs-to-role-during-a-destroy-operation/51305

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* vault >= 1.12.0 < 1.12.4
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= 1.11.0 < 1.11.8
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= None < 1.10.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vault 3.17-community 1.11.4-r3 Gennady Feldman <gena01@gmail.com> possibly vulnerable