Vulnerabilities > Hashicorp

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2021-30476 Unspecified vulnerability in Hashicorp Terraform Provider
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method.
network
low complexity
hashicorp
7.5
2021-04-22 CVE-2021-29653 Improper Certificate Validation vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL.
network
hashicorp CWE-295
4.3
2021-04-22 CVE-2021-27400 Improper Certificate Validation vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters.
network
low complexity
hashicorp CWE-295
5.0
2021-04-20 CVE-2020-25864 Cross-site Scripting vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting.
network
low complexity
hashicorp CWE-79
6.1
2021-04-20 CVE-2021-28156 Unspecified vulnerability in Hashicorp Consul
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events.
network
low complexity
hashicorp
7.5
2021-03-26 CVE-2021-3153 Improper Authentication vulnerability in Hashicorp Terraform Enterprise 2020071
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled.
network
low complexity
hashicorp CWE-287
4.0
2021-02-01 CVE-2021-3283 Unspecified vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node.
network
low complexity
hashicorp
5.0
2021-02-01 CVE-2021-3282 Improper Authentication vulnerability in Hashicorp Vault 1.6.0/1.6.1
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication.
network
low complexity
hashicorp CWE-287
7.5
2021-02-01 CVE-2021-3024 Unspecified vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests.
network
low complexity
hashicorp
5.0
2021-02-01 CVE-2020-25594 Unspecified vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests.
network
low complexity
hashicorp
5.0