漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vault vulnerable to LIST authorization bypass via trailing-slash strip
Vulnerability Description
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
HashiCorp Vault 授权问题漏洞
Vulnerability Description
HashiCorp Vault是美国HashiCorp公司开源的一个密码与密钥管理工具。 HashiCorp Vault 2.0.3之前版本和HashiCorp Vault Enterprise 2.0.3之前版本存在授权问题漏洞,该漏洞源于ACL策略引擎未能一致地针对带有尾斜杠的LIST请求执行通配符拒绝规则,可能导致持有更广泛允许规则和更狭窄通配符拒绝规则的令牌枚举其本应被拒绝访问的路径下的条目名称。
CVSS Information
N/A
Vulnerability Type
N/A