CVE-2023-5077

HIGH

Vault <1.13.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

Scores

CVSS v3 7.6
EPSS 0.0023
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266 CWE-732
Status published
Products (2)
hashicorp/vault 0 - 1.13.0Go
hashicorp/vault 0.10.0 - 1.13.0 (2 CPE variants)
Published Sep 29, 2023
Tracked Since Feb 18, 2026