CVE Vulnerabilities

CVE-2023-3775

Published: Sep 29, 2023 | Modified: Oct 02, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.

Affected Software

Name Vendor Start Version End Version
Vault Hashicorp 0.11.0 (including) 1.13.8 (excluding)
Vault Hashicorp 1.14.0 (including) 1.14.4 (excluding)

References