Vulnerabilities > Hashicorp

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-38698 Missing Authorization vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
network
low complexity
hashicorp CWE-862
4.0
2021-08-31 CVE-2021-27668 Missing Authentication for Critical Function vulnerability in Hashicorp Vault
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication.
network
low complexity
hashicorp CWE-306
5.0
2021-08-13 CVE-2021-38553 Improper Preservation of Permissions vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions.
local
low complexity
hashicorp CWE-281
4.4
2021-08-13 CVE-2021-38554 Improper Cross-boundary Removal of Sensitive Data vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser.
network
hashicorp CWE-212
3.5
2021-07-20 CVE-2021-36230 Incorrect Authorization vulnerability in Hashicorp Terraform
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner.
network
low complexity
hashicorp CWE-863
6.5
2021-07-17 CVE-2021-32574 Improper Certificate Validation vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name.
network
low complexity
hashicorp CWE-295
7.5
2021-07-17 CVE-2021-36213 Unspecified vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic.
network
low complexity
hashicorp
5.0
2021-06-17 CVE-2021-32575 Unspecified vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node.
low complexity
hashicorp
3.3
2021-06-03 CVE-2021-32923 Insufficient Session Expiration vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use.
network
high complexity
hashicorp CWE-613
7.4
2021-05-07 CVE-2021-32074 Information Exposure Through Log Files vulnerability in Hashicorp Vault-Action
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
network
low complexity
hashicorp CWE-532
5.0