Skip to content
VaultGHSA-gq98-53rq-qr5h

Hashicorp Vault vulnerable to Cross-site Scripting

Medium4.3CVE-2023-2121 · Published Jun 9, 2023 · updated Sep 10, 2026

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.11.111.11.11
>= 1.12.0, < 1.12.71.12.7
>= 1.13.0, < 1.13.31.13.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
BIT-vault-2023-2121, CVE-2023-2121, GO-2023-1849

More Vault advisories

All Vault
Advisory
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
Medium5.3Aug 1, 2023
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
High8.1Jul 6, 2023
HashiCorp Vault's revocation list not respected
Medium5.3Jul 6, 2023
HashiCorp Vault's PKI mount vulnerable to denial of service
Medium6.5Mar 30, 2023
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
Medium6.7Mar 30, 2023
HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks
Medium4.7Mar 30, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.