CVE-2024-9180

A privileged Vault operator with write permissions to the root namespaces identity endpoint could escalate their own or another users privileges to Vaults root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
HashiCorpCNA
7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
hashicorpvault
1.18.0 <
𝑥
< 1.18.0
hashicorpvault
1.18.0 <
𝑥
< 1.18.0
hashicorpvault
1.7.7 ≤
𝑥
≤ 1.17.7
hashicorpvault
1.7.7 ≤
𝑥
< 1.18.0
hashicorpvault
1.15.0 ≤
𝑥
< 1.15.16
hashicorpvault
1.16.0 ≤
𝑥
< 1.16.11
𝑥
= Vulnerable software versions