Bug 2241306 (CVE-2023-3775)
Summary: | CVE-2023-3775 hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | TEJ RATHI <trathi> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | amctagga, aoconnor, bniver, dfreiber, dsimansk, flucifre, gmeno, jburrell, jkoehler, lball, madam, matzew, mbenjamin, mhackett, mrajanna, muagarwa, nbecker, odf-bz-bot, rhuss, rogbas, shbose, sostapov, tnielsen, vereddy, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Vault Enterprise 1.15.0, 1.14.4, and 1.13.8 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the Vault Enterprise. A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in a denial of service.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2241310, 2241311, 2241312, 2241313, 2241314, 2241315, 2241316, 2241317, 2241318, 2241319, 2241320 | ||
Bug Blocks: | 2241308 |
Description
TEJ RATHI
2023-09-29 09:33:29 UTC
(In reply to TEJ RATHI from comment #0) > A Vault Enterprise Sentinel Role Governing Policy created by an operator to > restrict access to resources in one namespace can be applied to requests > outside in another non-descendant namespace, potentially resulting in denial > of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8. Does this suggest that updating projects' vault dependencies to one of these versions would fix the issue? This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:3718 https://access.redhat.com/errata/RHSA-2024:3718 |