Home
MEDIUM: 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.10.0 (semver) before 1.19.1
affected
Default status
unaffected
0.10.0 (semver) before 1.19.1
affected
Description
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
Problem types
CWE-863: Incorrect Authorization
Product status
0.10.0 (semver) before 1.19.1
0.10.0 (semver) before 1.19.1
References
discuss.hashicorp.com/...on-could-be-bypassed-on-login/74716