Vulnerabilities > CVE-2023-24999 - Incorrect Authorization vulnerability in Hashicorp Vault

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
hashicorp
CWE-863

Summary

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.

Vulnerable Configurations

Part Description Count
Application
Hashicorp
188

Common Weakness Enumeration (CWE)