The Vault and Vault Enterprise (Vault) Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vault | Hashicorp | 0.10.0 (including) | 1.13.0 (excluding) |
Red Hat OpenShift Container Platform 4.17 | RedHat | openshift4/ose-installer-rhel9:v4.17.0-202409122204.p0.gdfd4c08.assembly.stream.el9 | * |
RHODF-4.14-RHEL-9 | RedHat | odf4/odf-rhel9-operator:v4.14.0-18 | * |