Bug 2015915 (CVE-2021-41802) - CVE-2021-41802 vault: Incorrect Permission Assignment for Critical Resource
Summary: CVE-2021-41802 vault: Incorrect Permission Assignment for Critical Resource
Keywords:
Status: NEW
Alias: CVE-2021-41802
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2017239
Blocks: 2015916
TreeView+ depends on / blocked
 
Reported: 2021-10-20 10:46 UTC by Marian Rehak
Modified: 2025-03-17 23:44 UTC (History)
14 users (show)

Fixed In Version: vault 1.7.5. vault 1.8.4
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2021-10-20 10:46:32 UTC
HashiCorp Vault allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities.

Upstream Advisory:

https://discuss.hashicorp.com/t/hcsec-2021-27-vault-merging-multiple-entity-aliases-for-the-same-mount-may-allow-privilege-escalation/


Note You need to log in before you can comment on or make changes to this bug.