CVE-2023-2121

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
HashiCorpCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
hashicorpvault
𝑥
< 1.11.11
hashicorpvault
𝑥
< 1.11.11
hashicorpvault
1.12.0 ≤
𝑥
< 1.12.7
hashicorpvault
1.12.0 ≤
𝑥
< 1.12.7
hashicorpvault
1.13.0 ≤
𝑥
< 1.13.3
hashicorpvault
1.13.0 ≤
𝑥
< 1.13.3
𝑥
= Vulnerable software versions