HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vault | Hashicorp | 0.11.0 (including) | 1.7.5 (including) |
Vault | Hashicorp | 1.8.4 (including) | 1.8.4 (including) |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/bare-metal-event-relay-operator-bundle:v4.13.0-39 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/bare-metal-event-relay-rhel8-operator:v4.13.0-42 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/baremetal-hardware-event-proxy-rhel8:v4.13.0-21 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/topology-aware-lifecycle-manager-operator-bundle:v4.13.0-70 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/topology-aware-lifecycle-manager-precache-rhel8:v4.13.0-45 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/topology-aware-lifecycle-manager-recovery-rhel8:v4.13.0-43 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/topology-aware-lifecycle-manager-rhel8-operator:v4.13.0-70 | * |
Red Hat OpenShift Container Platform 4.13 | RedHat | openshift4/ztp-site-generate-rhel8:v4.13.0-45 | * |
RHODF-4.13-RHEL-9 | RedHat | odf4/odf-rhel9-operator:v4.13.0-24 | * |
RHODF-4.13-RHEL-9 | RedHat | odf4/rook-ceph-rhel9-operator:v4.13.0-70 | * |