Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 817794 (CVE-2021-42135) - app-admin/vault: Google Cloud credential disclosure (CVE-2021-42135)
Summary: app-admin/vault: Google Cloud credential disclosure (CVE-2021-42135)
Status: RESOLVED INVALID
Alias: CVE-2021-42135
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://discuss.hashicorp.com/t/hcsec...
Whiteboard: B4 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-10-11 14:05 UTC by John Helmert III
Modified: 2022-07-21 22:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-10-11 14:05:39 UTC
CVE-2021-42135:

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-12-01 16:31:10 UTC
Hm, no fixed version at URL?
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-07-21 22:12:31 UTC
Yeah, I guess there's really nothing packagers can do here.

"Remediation
Vault’s Google Cloud secrets engine documentation has been updated to provide additional guidance regarding roleset-related policy definition 4.

Vault operators using the Google Cloud secrets engine, particularly running Vault 1.8.0 and above, should review their Vault policies to ensure they meet their requirements and adhere to the principle of least privilege. They should specifically look for policy with endpoints and glob usage as noted above and consider moving to a wildcard."