Vulnerability CVE-2023-5834


Published: 2023-10-27   Modified: 2023-10-28

Description:
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.

 References:
https://discuss.hashicorp.com/t/hcsec-2023-31-vagrant-s-windows-installer-allowed-directory-junction-write/59568

Copyright 2026, cxsecurity.com

 

Back to Top