hashicorp vault CVE-2021-42135 is a vulnerability in HashiCorp Vault
Published on October 11, 2021

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.

NVD


Products Associated with CVE-2021-42135

Want to know whenever a new CVE is published for HashiCorp Vault? stack.watch will email you.

 

Exploit Probability

EPSS
0.19%
Percentile
40.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.