Vulnerabilities > Hashicorp > Low

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-10228 Incorrect Permission Assignment for Critical Resource vulnerability in Hashicorp Vagrant VMWare Utility
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes.
local
low complexity
hashicorp CWE-732
3.3
2023-07-20 CVE-2023-3299 Exposure of Resource to Wrong Sphere vulnerability in Hashicorp Nomad
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results.
network
low complexity
hashicorp CWE-668
2.7
2023-07-20 CVE-2023-3072 Missing Authorization vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results.
network
low complexity
hashicorp CWE-862
3.8
2023-05-01 CVE-2023-2197 Inadequate Encryption Strength vulnerability in Hashicorp Vault 1.13.0
HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key.
local
high complexity
hashicorp CWE-326
2.5