VaultGHSA-86c6-3g63-5w64
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
High7.6CVE-2023-5077 · Published Sep 29, 2023 · updated Sep 10, 2026
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.13.0 | 1.13.0 |
Details and references
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 92023 | Memory exhaustion in HashiCorp Vault | High7.5 | 1.13.12+2 more |
| Nov 92023 | HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability | High7.5 | 1.13.10+2 more |
| Sep 152023 | HashiCorp Vault Improper Input Validation vulnerability | Medium6.8 | 1.12.11+2 more |
| Aug 12023 | HashiCorp Vault and Vault Enterprise vulnerable to user enumeration | Medium5.3 | 1.13.5+1 more |
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation | High8.1 | 1.10.11+2 more |
| Jul 62023 | HashiCorp Vault's revocation list not respected | Medium5.3 | 1.9.10+2 more |