BIT-vault-2023-5077

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2023-5077.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-vault-2023-5077
Aliases
Published
2024-03-06T11:08:23.375Z
Modified
2025-05-20T10:02:07.006Z
Summary
Vault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets
Details

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / vault

Package

Name
vault
Purl
pkg:bitnami/vault

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0.10.0
Fixed
1.13.0