Vulnerability Description
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 0.11.0, < 1.13.8 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2023-29-vault-enterprise-s-sentinel-rgp-poVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2023-29-vault-enterprise-s-sentinel-rgp-poVendor Advisory
FAQ
What is CVE-2023-3775?
CVE-2023-3775 is a vulnerability with a CVSS score of 4.2 (MEDIUM). A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potent...
How severe is CVE-2023-3775?
CVE-2023-3775 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3775?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vault.