Skip to content
VaultGHSA-86c6-3g63-5w64

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

High7.6CVE-2023-5077 · Published Sep 29, 2023 · updated Sep 10, 2026

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.13.01.13.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266, CWE-732
Also known as
BIT-vault-2023-5077, CVE-2023-5077, GO-2023-2088

More Vault advisories

All Vault
Advisory
Memory exhaustion in HashiCorp Vault
High7.5Dec 9, 2023
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
High7.5Nov 9, 2023
HashiCorp Vault Improper Input Validation vulnerability
Medium6.8Sep 15, 2023
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
Medium5.3Aug 1, 2023
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
High8.1Jul 6, 2023
HashiCorp Vault's revocation list not respected
Medium5.3Jul 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.