CVE-2024-9180
ADVISORY - githubSummary
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16
EPSS Score: 0.00302 (0.531)
Common Weakness Enumeration (CWE)
ADVISORY - nist
ADVISORY - github
Incorrect Privilege Assignment
ADVISORY - gitlab
ADVISORY - redhat
Incorrect Privilege Assignment
NIST
CREATED
UPDATED
ADVISORY IDCVE-2024-9180
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.2highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-rr8j-7w34-xp5j
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.6highGoLang
CREATED
UPDATED
ADVISORY IDGO-2024-3191
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Bitnami
CREATED
UPDATED
ADVISORY ID
BIT-vault-2024-9180
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
7.2highRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2024-9180
EXPLOITABILITY SCORE
1.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.2highChainguard
CREATED
UPDATED
ADVISORY ID
CGA-9mc2-fx8q-8mwx
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-