Vulnerability Details CVE-2021-43998
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 5.5
Products affected by CVE-2021-43998
-
cpe:2.3:a:hashicorp:vault:0.11.0
-
cpe:2.3:a:hashicorp:vault:1.0.0
-
cpe:2.3:a:hashicorp:vault:1.0.1
-
cpe:2.3:a:hashicorp:vault:1.0.2
-
cpe:2.3:a:hashicorp:vault:1.0.3
-
cpe:2.3:a:hashicorp:vault:1.1.0
-
cpe:2.3:a:hashicorp:vault:1.1.1
-
cpe:2.3:a:hashicorp:vault:1.1.2
-
cpe:2.3:a:hashicorp:vault:1.1.3
-
cpe:2.3:a:hashicorp:vault:1.1.4
-
cpe:2.3:a:hashicorp:vault:1.1.5
-
cpe:2.3:a:hashicorp:vault:1.2.0
-
cpe:2.3:a:hashicorp:vault:1.2.1
-
cpe:2.3:a:hashicorp:vault:1.2.2
-
cpe:2.3:a:hashicorp:vault:1.2.3
-
cpe:2.3:a:hashicorp:vault:1.2.4
-
cpe:2.3:a:hashicorp:vault:1.2.5
-
cpe:2.3:a:hashicorp:vault:1.3.0
-
cpe:2.3:a:hashicorp:vault:1.3.1
-
cpe:2.3:a:hashicorp:vault:1.3.2
-
cpe:2.3:a:hashicorp:vault:1.3.3
-
cpe:2.3:a:hashicorp:vault:1.3.4
-
cpe:2.3:a:hashicorp:vault:1.3.5
-
cpe:2.3:a:hashicorp:vault:1.3.6
-
cpe:2.3:a:hashicorp:vault:1.3.8
-
cpe:2.3:a:hashicorp:vault:1.4.0
-
cpe:2.3:a:hashicorp:vault:1.4.1
-
cpe:2.3:a:hashicorp:vault:1.4.2
-
cpe:2.3:a:hashicorp:vault:1.4.3
-
cpe:2.3:a:hashicorp:vault:1.4.4
-
cpe:2.3:a:hashicorp:vault:1.4.5
-
cpe:2.3:a:hashicorp:vault:1.4.5.1
-
cpe:2.3:a:hashicorp:vault:1.4.6
-
cpe:2.3:a:hashicorp:vault:1.4.7
-
cpe:2.3:a:hashicorp:vault:1.5.0
-
cpe:2.3:a:hashicorp:vault:1.5.1
-
cpe:2.3:a:hashicorp:vault:1.5.2
-
cpe:2.3:a:hashicorp:vault:1.5.2.1
-
cpe:2.3:a:hashicorp:vault:1.5.3
-
cpe:2.3:a:hashicorp:vault:1.5.4
-
cpe:2.3:a:hashicorp:vault:1.5.5
-
cpe:2.3:a:hashicorp:vault:1.5.6
-
cpe:2.3:a:hashicorp:vault:1.5.7
-
cpe:2.3:a:hashicorp:vault:1.5.8
-
cpe:2.3:a:hashicorp:vault:1.5.9
-
cpe:2.3:a:hashicorp:vault:1.6.0
-
cpe:2.3:a:hashicorp:vault:1.6.1
-
cpe:2.3:a:hashicorp:vault:1.6.2
-
cpe:2.3:a:hashicorp:vault:1.6.3
-
cpe:2.3:a:hashicorp:vault:1.6.4
-
cpe:2.3:a:hashicorp:vault:1.6.5
-
cpe:2.3:a:hashicorp:vault:1.7.0
-
cpe:2.3:a:hashicorp:vault:1.7.1
-
cpe:2.3:a:hashicorp:vault:1.7.2
-
cpe:2.3:a:hashicorp:vault:1.7.3
-
cpe:2.3:a:hashicorp:vault:1.7.4
-
cpe:2.3:a:hashicorp:vault:1.7.5
-
cpe:2.3:a:hashicorp:vault:1.8.4