Vulnerabilities > Hashicorp > Vault > 1.5.0

DATE CVE VULNERABILITY TITLE RISK
2020-12-17 CVE-2020-35177 Information Exposure vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method.
network
low complexity
hashicorp CWE-200
5.0
2020-09-30 CVE-2020-25816 Unspecified vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly.
network
hashicorp
4.9
2020-08-26 CVE-2020-16251 Improper Authentication vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass.
network
low complexity
hashicorp CWE-287
8.2
2020-08-26 CVE-2020-16250 Authentication Bypass by Spoofing vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass.
network
low complexity
hashicorp CWE-290
8.2