5.4
CVSSv3

CVE-2023-2121

Published: 09/06/2023 Updated: 16/06/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp vault

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values This vulnerability, CVE-2023-2121, is fixed in Vault 1140, 1133, 1127, and 11111 ...