Database/Control plane, storage & DevOps
HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesets
CVSS 7.6CVE-2023-5077Control plane, storage & DevOpscurated
Impact
GCP secrets engine drops existing IAM Conditions when creating/updating rolesets -> over-broad cloud grants
Who can reach it
Network (remote)
What to do
Control-plane: upgrade + re-apply IAM conditions on all GCP rolesets
References
Related entries
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsCVE-2025-4166 · HashiCorp VaultMedium
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsCVE-2024-21985 · NetApp ONTAP 9 role-based access controlHigh
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesCVE-2025-3744 · HashiCorp Nomad EnterpriseHigh
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.