{"id":"GHSA-qv95-g3gm-x542","summary":"Hashicorp Vault Privilege Escalation Vulnerability","details":"HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.","aliases":["BIT-vault-2021-41802","CVE-2021-41802","GO-2022-0618"],"modified":"2026-07-17T21:05:28.010853866Z","published":"2021-10-12T16:39:01Z","database_specific":{"cwe_ids":["CWE-269","CWE-732"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2021-10-11T18:57:45Z","nvd_published_at":"2021-10-08T17:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41802"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2021-27-vault-merging-multiple-entity-aliases-for-the-same-mount-may-allow-privilege-escalation"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202207-01"}],"affected":[{"package":{"name":"github.com/hashicorp/vault","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-qv95-g3gm-x542/GHSA-qv95-g3gm-x542.json"}},{"package":{"name":"github.com/hashicorp/vault","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.8.0"},{"fixed":"1.8.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-qv95-g3gm-x542/GHSA-qv95-g3gm-x542.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N"}]}