blob: 95fc99631882c233ca41c1cd8e23e21395d7b6e2 [file] [log] [blame]
id: GO-2024-3191
modules:
- module: github.com/hashicorp/vault
versions:
- fixed: 1.18.0
vulnerable_at: 1.18.0-rc1
summary: Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault
cves:
- CVE-2024-9180
ghsas:
- GHSA-rr8j-7w34-xp5j
references:
- advisory: https://github.com/advisories/GHSA-rr8j-7w34-xp5j
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-9180
- web: https://discuss.hashicorp.com/t/hcsec-2024-21-vault-operators-in-root-namespace-may-elevate-their-privileges/70565
source:
id: GHSA-rr8j-7w34-xp5j
created: 2024-10-11T10:15:49.590706-04:00
review_status: UNREVIEWED