Excessive privileges In github.com/hashicorp/vault
Description
HashiCorp Vault Improper Privilege Management HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.3.4 | ||
go | v1.3.4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.