CVE-2023-5077 Vulnerability Details

  /     /     /  

CVE-2023-5077 Metadata Quick Info

CVE Published: 28/09/2023 | CVE Updated: 26/09/2024 | CVE Year: 2023
Source: HashiCorp | Vendor: HashiCorp | Product: Vault
Status : PUBLISHED

CVE-2023-5077 Description

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

Metrics

CVSS Version: 3.1 | Base Score: 7.6 HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-266
CWE Name: CWE-266: Incorrect Privilege Assignment
Source: HashiCorp

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-122
CAPEC Description: CAPEC-122: Privilege Abuse


Source: NVD (National Vulnerability Database).