Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Consul MEDIUM 6.1
CVE-2024-10086

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allow…

Fix: 1.15.15 / 1.18.5+
Fix from $1,600 2024-10-30
Consul MEDIUM 5.8
CVE-2024-10006

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header b…

Fix: 1.15.15 / 1.18.5+
Fix from $1,600 2024-10-30
Consul MEDIUM 5.8
CVE-2024-10005

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP reques…

Fix: 1.15.15 / 1.18.5+
Fix from $1,600 2024-10-30
Vault HIGH 8.8
CVE-2024-7594

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields o…

Fix: 1.15.15 / 1.16.10+
Fix from $1,950 2024-09-26
Vault MEDIUM 6.5
CVE-2024-8365

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit devic…

Fix: 1.16.9 / 1.17.5+
Fix from $1,600 2024-09-02
Nomad MEDIUM 5.8
CVE-2024-7625

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the…

Fix: 1.6.14 / 1.7.11+
Fix from $1,600 2024-08-15
Nomad HIGH 8.6
CVE-2024-6717

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocatio…

Fix: 1.7.10+
Fix from $1,950 2024-07-23
Vault HIGH 7.5
CVE-2024-6468

Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_b…

Fix: 1.15.12 / 1.16.6+
Fix from $1,950 2024-07-11
Go Getter HIGH 8.8
CVE-2024-6257

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to …

Fix: 1.7.5+
Fix from $1,950 2024-06-25
Retryablehttp MEDIUM 5.5
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP b…

Fix: 0.7.7+
Fix from $1,600 2024-06-24
Vault HIGH 7.5
CVE-2024-5798

Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This ma…

Fix: 1.15.9 / 1.16.3+
Fix from $1,950 2024-06-12
Vault MEDIUM 5.5
CVE-2024-2877

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby…

Fix: 1.15.8+
Fix from $1,600 2024-04-30
Go Getter CRITICAL 9.8
CVE-2024-3817

HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affec…

Fix: 1.7.4+
Fix from $2,300 2024-04-17
Vault MEDIUM 6.8
CVE-2024-2660

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This…

Fix: 1.14.11 / 1.15.7+
Fix from $1,600 2024-04-04
Vault CRITICAL 9.8
CVE-2024-2048

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…

Fix: 1.14.10 / 1.15.5+
Fix from $2,300 2024-03-04
Nomad HIGH 7.5
CVE-2024-1329

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad c…

Fix: 1.5.14 / 1.6.7+
Fix from $1,950 2024-02-08
Boundary HIGH 8.0
CVE-2024-1052

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to en…

Fix: 0.15.0+
Fix from $1,950 2024-02-05
Vault MEDIUM 6.5
CVE-2024-0831

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may l…

Fix: 1.15.5+
Fix from $1,600 2024-02-01
Vault HIGH 7.5
CVE-2023-6337

HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large…

Fix: 1.13.12 / 1.14.8+
Fix from $1,950 2023-12-08
Vault HIGH 7.5
CVE-2023-5954

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number…

Fix: 1.13.10 / 1.14.6+
Fix from $1,950 2023-11-09
Vagrant HIGH 7.8
CVE-2023-5834

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauth…

Fix: 2.4.0+
Fix from $1,950 2023-10-27
Vault HIGH 7.5
CVE-2023-5077

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating …

Fix: 1.13.0+
Fix from $1,950 2023-09-29
Vault MEDIUM 6.8
CVE-2023-4680

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption dis…

Fix: 1.12.11 / 1.13.7+
Fix from $1,600 2023-09-15
Terraform HIGH 7.8
CVE-2023-4782

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. …

Fix: 1.5.7+
Fix from $1,950 2023-09-08
Consul HIGH 7.3
CVE-2023-3518

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities.…

Mitigation only
Fix from $1,950 2023-08-09
Vault MEDIUM 5.3
CVE-2023-3462

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existen…

Fix: 1.13.5+
Fix from $1,600 2023-07-31
Nomad MEDIUM 5.3
CVE-2023-3300

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users …

Fix: after 1.5.6
Fix from $1,600 2023-07-20
Terraform Enterprise HIGH 7.7
CVE-2023-3114

Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unautho…

Fix: 202306-1+
Fix from $1,950 2023-06-22
Vault MEDIUM 5.4
CVE-2023-2121

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerabi…

Fix: 1.11.11 / 1.12.7+
Fix from $1,600 2023-06-09
Consul HIGH 7.5
CVE-2023-1297

Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local servic…

Fix: 1.14.7 / 1.15.3+
Fix from $1,950 2023-06-02