Vulnerabilities > Hashicorp

DATE CVE VULNERABILITY TITLE RISK
2023-12-08 CVE-2023-6337 Allocation of Resources Without Limits or Throttling vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client.
network
low complexity
hashicorp CWE-770
7.5
2023-12-04 CVE-2023-5332 Patch in third party library Consul requires 'enable-script-checks' to be set to False.
network
high complexity
gitlab hashicorp
8.1
2023-11-09 CVE-2023-5954 Memory Leak vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory.
network
low complexity
hashicorp CWE-401
7.5
2023-10-27 CVE-2023-5834 Link Following vulnerability in Hashicorp Vagrant
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes.
local
low complexity
hashicorp CWE-59
7.8
2023-09-29 CVE-2023-3775 Unspecified vulnerability in Hashicorp Vault
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service.
network
low complexity
hashicorp
4.9
2023-09-29 CVE-2023-5077 Incorrect Permission Assignment for Critical Resource vulnerability in Hashicorp Vault
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets.
network
low complexity
hashicorp CWE-732
7.5
2023-09-15 CVE-2023-4680 Improper Input Validation vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled.
network
high complexity
hashicorp CWE-20
6.8
2023-09-08 CVE-2023-4782 Path Traversal vulnerability in Hashicorp Terraform
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration.
local
low complexity
hashicorp CWE-22
7.8
2023-08-09 CVE-2023-3518 Unspecified vulnerability in Hashicorp Consul 1.16.0
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities.
network
low complexity
hashicorp
7.3
2023-07-31 CVE-2023-3462 Information Exposure Through Discrepancy vulnerability in Hashicorp Vault 1.13.0/1.13.4/1.14.0
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method.
network
low complexity
hashicorp CWE-203
5.3