{"id":"GHSA-j6vv-vv26-rh7c","summary":"HashiCorp Vault Improper Privilege Management","details":"HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.","aliases":["BIT-vault-2020-10661","CVE-2020-10661","GO-2024-2485"],"modified":"2024-09-16T15:06:33Z","published":"2024-01-30T23:40:40Z","database_specific":{"severity":"CRITICAL","cwe_ids":["CWE-269"],"github_reviewed_at":"2024-01-30T23:40:40Z","github_reviewed":true,"nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10661"},{"type":"WEB","url":"https://github.com/hashicorp/vault/commit/18485ee9d4352ac8e8396c580b5941ccf8e5b31a"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault"},{"type":"WEB","url":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020"},{"type":"WEB","url":"https://www.hashicorp.com/blog/category/vault"}],"affected":[{"package":{"name":"github.com/hashicorp/vault","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.11.0"},{"fixed":"1.3.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-j6vv-vv26-rh7c/GHSA-j6vv-vv26-rh7c.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}