Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Consul MEDIUM 6.5
CVE-2023-2816

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote …

Fix: 1.15.3+
Fix from $1,600 2023-06-02
Nomad CRITICAL 9.8
CVE-2023-1782

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where …

Fix: after 1.5.2
Fix from $2,300 2023-04-05
Vault MEDIUM 6.7
CVE-2023-0620

HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQ…

Fix: 1.11.9 / 1.12.5+
Fix from $1,600 2023-03-30
Vault MEDIUM 6.5
CVE-2023-0665

HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting …

Fix: 1.11.9 / 1.12.5+
Fix from $1,600 2023-03-30
Nomad HIGH 8.8
CVE-2023-1299

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fix…

Mitigation only
Fix from $1,950 2023-03-14
Nomad MEDIUM 5.3
CVE-2023-1296

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and …

Fix: 1.4.6+
Fix from $1,600 2023-03-14
Vault HIGH 8.1
CVE-2023-24999

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the s…

Fix: 1.10.11 / 1.11.8+
Fix from $1,950 2023-03-11
Consul MEDIUM 6.5
CVE-2023-0845

Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client …

Fix: 1.14.5+
Fix from $1,600 2023-03-09
Nomad MEDIUM 6.5
CVE-2023-0821

HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive dis…

Fix: 1.2.15 / 1.3.9+
Fix from $1,600 2023-02-16
Go Getter MEDIUM 6.5
CVE-2023-0475

HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.

Fix: after 1.6.2
Fix from $1,600 2023-02-16
Boundary HIGH 7.1
CVE-2023-0690

HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the…

Fix: 0.12.0+
Fix from $1,950 2023-02-08
Nomad MEDIUM 5.3
CVE-2019-14802

HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GH…

Fix: 0.9.5+
Fix from $1,600 2022-12-26
Consul HIGH 7.5
CVE-2022-3920

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us…

Fix: after 1.13.3
Fix from $1,950 2022-11-16
Boundary MEDIUM 6.1
CVE-2022-36182

Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sit…

Fix: 0.11.0+
Fix from $1,600 2022-10-27
Vault MEDIUM 5.3
CVE-2022-41316

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into …

Fix: 1.9.10 / 1.10.7+
Fix from $1,600 2022-10-12
Nomad MEDIUM 6.5
CVE-2022-41606

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to…

Fix: 1.2.13 / 1.3.6+
Fix from $1,600 2022-10-12
Vagrant HIGH 7.8
CVE-2022-42717

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has bee…

Fix: 2.3.1+
Fix from $1,950 2022-10-11
Consul MEDIUM 6.5
CVE-2022-40716

HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoin…

Fix: 1.11.9 / 1.12.5+
Fix from $1,600 2022-09-23
Consul HIGH 7.1
CVE-2021-41803

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT cl…

Fix: 1.11.9+
Fix from $1,950 2022-09-23
Vault CRITICAL 9.1
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deploymen…

Fix: 1.9.9 / 1.10.6+
Fix from $2,300 2022-09-22
Boundary CRITICAL 9.9
CVE-2022-36130

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allow…

Fix: 0.10.2+
Fix from $2,300 2022-09-01
Consul Template HIGH 7.5
CVE-2022-38149

HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.E…

Fix: 0.29.2+
Fix from $1,950 2022-08-17
Vault CRITICAL 9.1
CVE-2022-36129

HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul…

Fix: after 1.10.4
Fix from $2,300 2022-07-26
Nomad CRITICAL 9.8
CVE-2022-30324

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the a…

Fix: 1.1.14 / 1.2.8+
Fix from $2,300 2022-06-02
Go Getter CRITICAL 9.8
CVE-2022-26945

go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header proc…

Fix: after 1.5.11
Fix from $2,300 2022-05-25
Go Getter HIGH 8.6
CVE-2022-30321

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i…

Fix: after 1.5.11
Fix from $1,950 2022-05-25
Go Getter HIGH 8.6
CVE-2022-30322

go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.

Fix: after 1.5.11
Fix from $1,950 2022-05-25
Go Getter HIGH 8.6
CVE-2022-30323

go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.

Fix: after 1.5.11
Fix from $1,950 2022-05-25
Vault MEDIUM 5.3
CVE-2022-30689

HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects t…

Fix: 1.10.3+
Fix from $1,600 2022-05-17
Go Getter MEDIUM 5.5
CVE-2022-29810

The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

Fix: 1.5.11+
Fix from $1,600 2022-04-27