Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.10.4 (semver) before 1.20.0
affected
Default status
unaffected
0.10.4 (semver) before 1.20.0
affected
Description
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
Problem types
CWE-266: Incorrect Privilege Assignment
Product status
0.10.4 (semver) before 1.20.0
0.10.4 (semver) before 1.20.0
References
discuss.hashicorp.com/...-may-elevate-token-privileges/76032