| Summary: | app-admin/vault: Google Cloud credential disclosure (CVE-2021-42135) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED INVALID | ||
| Severity: | minor | CC: | zmedico |
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://discuss.hashicorp.com/t/hcsec-2021-28-vaults-google-cloud-secrets-engine-policies-with-globs-may-provide-additional-privileges-in-vault-1-8-0-onwards | ||
| Whiteboard: | B4 [ebuild] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
John Helmert III
2021-10-11 14:05:39 UTC
Hm, no fixed version at URL? Yeah, I guess there's really nothing packagers can do here. "Remediation Vault’s Google Cloud secrets engine documentation has been updated to provide additional guidance regarding roleset-related policy definition 4. Vault operators using the Google Cloud secrets engine, particularly running Vault 1.8.0 and above, should review their Vault policies to ensure they meet their requirements and adhere to the principle of least privilege. They should specifically look for policy with endpoints and glob usage as noted above and consider moving to a wildcard." |