Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
High severity
GitHub Reviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Jul 6, 2023
Package
Affected versions
< 1.10.11
>= 1.11.0, < 1.11.8
>= 1.12.0, < 1.12.4
Patched versions
1.10.11
1.11.8
1.12.4
Description
Published by the National Vulnerability Database
Mar 11, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Reviewed
Jul 6, 2023
Last updated
Jul 6, 2023
When using the Vault and Vault Enterprise (Vault) approle auth method, any authenticated user with access to the
/auth/approle/role/:role_name/secret-id-accessor/destroy
endpoint can destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability, CVE-2023-24999, has been fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.References