VDB
CVE-2024-9180
CVE-2024-9180
PUBLISHED
CVSS 7.199999809265137 HIGH
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.
EPSS 0.52% · 42.4th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.52%
42.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 1.7.7 |
| Bitnami | vault | 1.7.7 |
Timeline
- Oct 10, 2024 CVE Published
- Oct 11, 2024 EPSS Score
- Oct 11, 2024 PoC Published
- Oct 14, 2024 Coalition ESS Score
- Oct 17, 2024 Coalition ESS Score
- Oct 17, 2024 Coalition ESS Score
- Oct 18, 2024 Coalition ESS Score
- Oct 30, 2024 EPSS Score
- Nov 19, 2024 EPSS Score
- Dec 9, 2024 EPSS Score
- Dec 28, 2024 EPSS Score
- Jan 17, 2025 EPSS Score