Skip to content
VagrantGHSA-47xw-vw6m-w9fq

HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability

Low3.8CVE-2023-5834 · Published Oct 28, 2023 · updated Nov 8, 2023

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vagrant
Go
< 2.4.02.4.0
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1386, CWE-59
Also known as
CVE-2023-5834

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.