CVE-2023-24999

MEDIUM

HashiCorp Vault < 1.10.11 - Authenticated Incorrect Authorization via AppRole Secret ID Destroy Endpoint

Title source: llm
STIX 2.1

Description

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.

Scores

CVSS v3 4.4
EPSS 0.0018
EPSS Percentile 39.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
hashicorp/vault < 1.10.11 (2 CPE variants)
hashicorp/vault 0 - 1.10.11Go
Published Mar 11, 2023
Tracked Since Feb 18, 2026