Bug 2184663 (CVE-2023-0620) - CVE-2023-0620 vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
Summary: CVE-2023-0620 vault: Vault’s Microsoft SQL Database Storage Backend Vulnerabl...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2023-0620
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2184664 2184665 2184666 2184667 2184668 2184669 2184670
Blocks: 2184572
TreeView+ depends on / blocked
 
Reported: 2023-04-05 11:35 UTC by Avinash Hanwate
Modified: 2023-10-31 12:54 UTC (History)
12 users (show)

Fixed In Version: Vault 1.13.1, Vault 1.12.5, and 1.11.9
Doc Type: ---
Doc Text:
A flaw was found in HashiCorp Vault and Vault Enterprise, which are vulnerable to SQL injection. This flaw allows a local authenticated attacker to send specially-crafted SQL statements to the Microsoft SQL (MSSQL) Database Storage Backend, which could allow the attacker to view, add, modify, or delete information in the backend database.
Clone Of:
Environment:
Last Closed: 2023-05-18 04:48:39 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:1326 0 None None None 2023-05-17 22:31:55 UTC
Red Hat Product Errata RHSA-2023:3742 0 None None None 2023-06-22 19:52:32 UTC
Red Hat Product Errata RHSA-2023:5006 0 None None None 2023-10-31 12:54:43 UTC

Description Avinash Hanwate 2023-04-05 11:35:12 UTC
HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command. This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.

https://discuss.hashicorp.com/t/hcsec-2023-12-vault-s-microsoft-sql-database-storage-backend-vulnerable-to-sql-injection-via-configuration-file/52080/1

Comment 3 errata-xmlrpc 2023-05-17 22:31:53 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2023:1326 https://access.redhat.com/errata/RHSA-2023:1326

Comment 4 Product Security DevOps Team 2023-05-18 04:48:36 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-0620

Comment 5 errata-xmlrpc 2023-06-22 19:52:31 UTC
This issue has been addressed in the following products:

  RHODF-4.13-RHEL-9

Via RHSA-2023:3742 https://access.redhat.com/errata/RHSA-2023:3742

Comment 6 errata-xmlrpc 2023-10-31 12:54:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2023:5006 https://access.redhat.com/errata/RHSA-2023:5006


Note You need to log in before you can comment on or make changes to this bug.