Bug 2317923 (CVE-2024-9180)

Summary: CVE-2024-9180 hashicorp/vault: Vault Operators in Root Namespace May Elevate Their Privileges
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: amctagga, manissin, mrajanna, muagarwa, tnielsen, ypadia
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in HashiCorp Vault. This vulnerability allows a privileged Vault operator with write permissions to the root namespace's identity endpoint to escalate their privileges to Vault’s root policy. A misconfiguration in Vault allows a privileged operator (someone with write permissions on the root namespace’s identity endpoint) to elevate privileges—either their own or another user’s—to the root policy level, effectively giving full administrative control.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2317995, 2317996, 2317997, 2317998, 2317999    
Bug Blocks:    

Description OSIDB Bzimport 2024-10-10 21:01:51 UTC
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.