CVE-2023-2121: Hashicorp Vault
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.
Affected products
- Hashicorp Vault: before 1.11.11 (fixed in 1.11.11); from 1.12.0, before 1.12.7 (fixed in 1.12.7); from 1.13.0, before 1.13.3 (fixed in 1.13.3)
Published 2023-06-09. Last modified 2026-06-17.