ZeroHour

CVE-2023-5077

CVSS 3.1
7.5 high
EPSS
<1%p37
Published
()
Modified
Description

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

Vendors
hashicorp
Products
vault
Weakness
CWE-266, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.