Security Advisory

CVE-2023-24999

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-10 23:12:47
Last updated 2025-03-03 20:46:23
Assigner HashiCorp
State PUBLISHED

Description

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.