Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 872686 (CVE-2022-40186) - <app-admin/vault-1.11.3: entity alias metadata leakage
Summary: <app-admin/vault-1.11.3: entity alias metadata leakage
Status: RESOLVED FIXED
Alias: CVE-2022-40186
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://discuss.hashicorp.com/t/hcsec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-09-24 19:15 UTC by John Helmert III
Modified: 2022-09-26 14:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-24 19:15:19 UTC
CVE-2022-40186:

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

Please stabilize 1.11.3, or bump to 1.10.6 and stabilize.
Comment 1 Larry the Git Cow gentoo-dev 2022-09-24 20:08:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f29e930aa10484145c1e4cea921df66d4ece9228

commit f29e930aa10484145c1e4cea921df66d4ece9228
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-24 20:07:28 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-24 20:08:10 +0000

    app-admin/vault: drop 1.10.5, 1.11.1, 1.11.2
    
    Bug: https://bugs.gentoo.org/872686
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/vault/Manifest            |  6 ---
 app-admin/vault/vault-1.10.5.ebuild | 85 ------------------------------------
 app-admin/vault/vault-1.11.1.ebuild | 86 -------------------------------------
 app-admin/vault/vault-1.11.2.ebuild | 86 -------------------------------------
 4 files changed, 263 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=eacc41755dc5e7cb32672a92ad111735b8944b89

commit eacc41755dc5e7cb32672a92ad111735b8944b89
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-24 20:06:37 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-24 20:08:10 +0000

    app-admin/vault: stabilize 1.10.6 for amd64
    
    Bug: https://bugs.gentoo.org/872686
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/vault/vault-1.10.6.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-24 20:10:53 UTC
Thanks Zac!
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-26 14:05:04 UTC
Not obviously exploitable, no GLSA.