{"id":"CVE-2023-5077","aliases":["GHSA-86c6-3g63-5w64","BIT-vault-2023-5077","GO-2023-2088"],"title":"Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability","summary":"Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability","severity":"high","cvss":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","vendor":"hashicorp","product":"github.com/hashicorp/vault","ecosystem":"go","affected":["github.com/hashicorp/vault < 1.13.0"],"patched":["github.com/hashicorp/vault 1.13.0"],"published":"2023-09-29","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:58.086222547Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-86c6-3g63-5w64","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5077"},{"url":"https://discuss.hashicorp.com/t/hcsec-2023-30-vault-s-google-cloud-secrets-engine-removed-existing-iam-conditions-when-creating-updating-rolesets/58654"},{"url":"https://github.com/hashicorp/vault"}],"tags":["osv","go"],"epss":0.00436,"epssPercentile":0.37392,"ingestedAt":"2026-09-12T03:13:01.766Z","slug":"CVE-2023-5077","body":"## Overview\n\nThe Vault and Vault Enterprise (\"Vault\") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.\n\n## Affected packages\n\n- `github.com/hashicorp/vault < 1.13.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/hashicorp/vault 1.13.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}