Vulnerabilities > Hashicorp > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-10 CVE-2024-9180 Unspecified vulnerability in Hashicorp Vault
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy.
network
low complexity
hashicorp
7.2
2024-02-08 CVE-2024-1329 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Hashicorp Nomad 1.5.13/1.6.6/1.7.3.
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks.
network
low complexity
hashicorp CWE-610
7.5
2024-02-05 CVE-2024-1052 Improper Certificate Validation vulnerability in Hashicorp Boundary
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering.
network
high complexity
hashicorp CWE-295
8.0
2023-12-08 CVE-2023-6337 Allocation of Resources Without Limits or Throttling vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client.
network
low complexity
hashicorp CWE-770
7.5
2023-12-04 CVE-2023-5332 Patch in third party library Consul requires 'enable-script-checks' to be set to False.
network
high complexity
gitlab hashicorp
8.1
2023-11-09 CVE-2023-5954 Memory Leak vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory.
network
low complexity
hashicorp CWE-401
7.5
2023-10-27 CVE-2023-5834 Link Following vulnerability in Hashicorp Vagrant
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes.
local
low complexity
hashicorp CWE-59
7.8
2023-09-29 CVE-2023-5077 Incorrect Permission Assignment for Critical Resource vulnerability in Hashicorp Vault
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets.
network
low complexity
hashicorp CWE-732
7.5
2023-09-08 CVE-2023-4782 Path Traversal vulnerability in Hashicorp Terraform
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration.
local
low complexity
hashicorp CWE-22
7.8
2023-08-09 CVE-2023-3518 Unspecified vulnerability in Hashicorp Consul 1.16.0
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities.
network
low complexity
hashicorp
7.3