Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
0.8.0 (semver) before 1.20.1
affected
Default status
unaffected
0.8.0 (semver) before 1.20.1
affected
Description
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Problem types
CWE-94: Improper Control of Generation of Code (Code Injection)
Product status
0.8.0 (semver) before 1.20.1
0.8.0 (semver) before 1.20.1
References
discuss.hashicorp.com/...e-code-on-the-underlying-host/76033