CVE-2021-41802

LOW

Hashicorp Vault < 1.7.5 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

References (2)

Core 2

Scores

CVSS v3 2.9
EPSS 0.0025
EPSS Percentile 48.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

Details

CWE
CWE-732
Status published
Products (2)
hashicorp/vault < 1.7.5 (2 CPE variants)
hashicorp/vault 0 - 1.7.5Go
Published Oct 08, 2021
Tracked Since Feb 18, 2026