VaultGHSA-gq98-53rq-qr5h
Hashicorp Vault vulnerable to Cross-site Scripting
Medium4.3CVE-2023-2121 · Published Jun 9, 2023 · updated Sep 10, 2026
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.11.11 | 1.11.11 |
| >= 1.12.0, < 1.12.7 | 1.12.7 | |
| >= 1.13.0, < 1.13.3 | 1.13.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- BIT-vault-2023-2121, CVE-2023-2121, GO-2023-1849
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12023 | HashiCorp Vault and Vault Enterprise vulnerable to user enumeration | Medium5.3 | 1.13.5+1 more |
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation | High8.1 | 1.10.11+2 more |
| Jul 62023 | HashiCorp Vault's revocation list not respected | Medium5.3 | 1.9.10+2 more |
| Mar 302023 | HashiCorp Vault's PKI mount vulnerable to denial of service | Medium6.5 | 1.11.9+2 more |
| Mar 302023 | HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File | Medium6.7 | 1.11.9+2 more |
| Mar 302023 | HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks | Medium4.7 | 1.11.9+2 more |