Incorrect Privilege Assignment Affecting github.com/hashicorp/vault/command/agentproxyshared/cache package, versions <1.18.0
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMHASHICORPVAULTCOMMANDAGENTPROXYSHAREDCACHE-8184980
- published 13 Oct 2024
- disclosed 11 Oct 2024
- credit Vault engineering team
Introduced: 11 Oct 2024
CVE-2024-9180 Open this link in a new tabHow to fix?
Upgrade github.com/hashicorp/vault/command/agentproxyshared/cache
to version 1.18.0 or higher.
Overview
Affected versions of this package are vulnerable to Incorrect Privilege Assignment due to the mishandling of entries in an in-memory cache, a privileged operators could manipulate their cached record through an API endpoint on a node, potentially escalating their privileges to the highest level policy on this node.
Note:
This is only exploitable if the operator has write permissions to the root namespace's identity endpoint and does not affect entities in namespaces (including administrative namespaces).