Vulnerabilities > Hashicorp > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-20 CVE-2023-3300 Missing Authorization vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy.
network
low complexity
hashicorp CWE-862
5.3
2023-06-09 CVE-2023-2121 Cross-site Scripting vulnerability in Hashicorp Vault
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values.
network
low complexity
hashicorp CWE-79
5.4
2023-06-02 CVE-2023-2816 Unspecified vulnerability in Hashicorp Consul 1.15.0
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
network
low complexity
hashicorp
6.5
2023-03-30 CVE-2023-0620 SQL Injection vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend.
local
low complexity
hashicorp CWE-89
6.7
2023-03-30 CVE-2023-0665 Unspecified vulnerability in Hashicorp Vault
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount.
network
low complexity
hashicorp
6.5
2023-03-30 CVE-2023-25000 Information Exposure Through Discrepancy vulnerability in Hashicorp Vault
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks.
local
high complexity
hashicorp CWE-203
4.7
2023-03-14 CVE-2023-1296 Missing Authorization vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables.
network
low complexity
hashicorp CWE-862
5.3
2023-03-09 CVE-2023-0845 NULL Pointer Dereference vulnerability in Hashicorp Consul
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances.
network
low complexity
hashicorp CWE-476
6.5
2023-02-16 CVE-2023-0821 Unspecified vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage.
network
low complexity
hashicorp
6.5
2023-02-16 CVE-2023-0475 Unspecified vulnerability in Hashicorp Go-Getter
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs.
network
low complexity
hashicorp
6.5