Vulnerabilities > Hashicorp > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-1782 Missing Authorization vulnerability in Hashicorp Nomad 1.5.0
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled.
network
low complexity
hashicorp CWE-862
critical
9.8
2022-09-22 CVE-2022-40186 Unspecified vulnerability in Hashicorp Vault
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.
network
low complexity
hashicorp
critical
9.1
2022-09-01 CVE-2022-36130 Insufficient Verification of Data Authenticity vulnerability in Hashicorp Boundary
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope.
network
low complexity
hashicorp CWE-345
critical
9.9
2022-07-26 CVE-2022-36129 Missing Authentication for Critical Function vulnerability in Hashicorp Vault
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure.
network
low complexity
hashicorp CWE-306
critical
9.1
2022-06-02 CVE-2022-30324 Unspecified vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host.
network
low complexity
hashicorp
critical
9.8
2022-05-25 CVE-2022-26945 Unspecified vulnerability in Hashicorp Go-Getter
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing.
network
low complexity
hashicorp
critical
9.8
2021-04-22 CVE-2021-30476 Unspecified vulnerability in Hashicorp Terraform Provider
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method.
network
low complexity
hashicorp
critical
9.8
2020-12-17 CVE-2020-35192 Missing Authentication for Critical Function vulnerability in Hashicorp Vault
The official vault docker images before 0.11.6 contain a blank password for a root user.
network
low complexity
hashicorp CWE-306
critical
9.8
2020-12-08 CVE-2020-29564 Unspecified vulnerability in Hashicorp Consul Docker Image
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.
network
low complexity
hashicorp
critical
9.8
2020-10-22 CVE-2020-27195 Unspecified vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas.
network
low complexity
hashicorp
critical
9.1