A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.14.0"
},
{
"fixed": "1.14.4"
},
{
"introduced": "1.13.0"
},
{
"fixed": "1.13.8"
},
{
"introduced": "0.11.0"
},
{
"fixed": "1.13.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-266"
],
"cna_assigner": "HashiCorp",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3775.json"
}