CVE-2021-42135

CVE-2021-42135

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.

Source: CVE-2021-42135

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다