GHSA-86c6-3g63-5w64
GitHub Security Advisory
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
Affected Packages
Go
github.com/hashicorp/vault
Affected versions:
0
(fixed in 1.13.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 7, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.