Loading HuntDB...

GHSA-jg74-mwgw-v6x3

GitHub Security Advisory

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

Affected Packages

Go github.com/hashicorp/vault
Affected versions: 1.7.7 (fixed in 1.17.6)

Related CVEs

Key Information

GHSA ID
GHSA-jg74-mwgw-v6x3
Published
September 26, 2024 9:31 PM
Last Modified
January 10, 2025 3:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/vault
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.