Vulnerability Description
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | < 1.7.5 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2021-27-vault-merging-multiple-entity-aliaVendor Advisory
- https://security.gentoo.org/glsa/202207-01Third Party Advisory
- https://discuss.hashicorp.com/t/hcsec-2021-27-vault-merging-multiple-entity-aliaVendor Advisory
- https://security.gentoo.org/glsa/202207-01Third Party Advisory
FAQ
What is CVE-2021-41802?
CVE-2021-41802 is a vulnerability with a CVSS score of 2.9 (LOW). HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies...
How severe is CVE-2021-41802?
CVE-2021-41802 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41802?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vault.