CVE-2023-5077: Hashicorp Vault
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
Affected products
- Hashicorp Vault: from 0.10.0, before 1.13.0 (fixed in 1.13.0)
Published 2023-09-29. Last modified 2026-06-17.