Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sentinel HIGH 7.5
CVE-2021-44139EPSS 6%

Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).

No fix yet
Fix from $1,950 2022-03-23
Vault MEDIUM 6.5
CVE-2022-25243

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates…

Fix: 1.8.9 / 1.9.4+
Fix from $1,600 2022-03-10
Vault MEDIUM 6.5
CVE-2022-25244

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoin…

Fix: 1.7.10 / 1.8.9+
Fix from $1,600 2022-03-10
Nomad HIGH 7.5
CVE-2022-24685

HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fi…

Fix: 1.1.12 / 1.2.6+
Fix from $1,950 2022-02-28
Terraform Enterprise HIGH 7.5
CVE-2022-25374

HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may captu…

Fix: 202202-1+
Fix from $1,950 2022-02-25
Consul MEDIUM 6.5
CVE-2022-24687

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:…

Fix: 1.9.15 / 1.10.8+
Fix from $1,600 2022-02-24
Nomad HIGH 7.5
CVE-2022-24683

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities…

Fix: 1.0.18 / 1.1.12+
Fix from $1,950 2022-02-17
Nomad MEDIUM 6.5
CVE-2022-24684

HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to…

Fix: 1.0.18 / 1.1.12+
Fix from $1,600 2022-02-15
Nomad MEDIUM 5.9
CVE-2022-24686

HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad…

Fix: 1.0.18 / 1.1.12+
Fix from $1,600 2022-02-14
Consul HIGH 8.8
CVE-2021-41805EPSS 35%

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default…

Fix: 1.8.17 / 1.9.11+
Fix from $1,950 2021-12-12
Nomad HIGH 8.8
CVE-2021-43415

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submissi…

Fix: 1.0.14 / 1.1.8+
Fix from $1,950 2021-12-03
Vault MEDIUM 6.5
CVE-2021-43998

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multipl…

Fix: after 1.7.5
Fix from $1,600 2021-11-30
Vault HIGH 8.1
CVE-2021-42135

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secret…

Fix: after 1.8.4
Fix from $1,950 2021-10-11
Vault MEDIUM 5.4
CVE-2021-41802

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with…

Fix: 1.7.5 / 1.8.4+
Fix from $1,600 2021-10-08
Nomad MEDIUM 6.5
CVE-2021-41865

HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by s…

Fix: 1.1.6+
Fix from $1,600 2021-10-07
Terraform Enterprise HIGH 8.8
CVE-2021-40862

HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which c…

Fix: after 202108-1
Fix from $1,950 2021-09-15
Nomad HIGH 8.8
CVE-2021-37218

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only fun…

Fix: 1.0.10 / 1.1.4+
Fix from $1,950 2021-09-07
Consul HIGH 8.8
CVE-2021-37219

HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…

Fix: 1.8.15 / 1.9.9+
Fix from $1,950 2021-09-07
Consul MEDIUM 6.5
CVE-2021-38698

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service …

Fix: 1.8.15 / 1.9.9+
Fix from $1,600 2021-09-07
Vault MEDIUM 5.3
CVE-2021-27668

HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.

Fix: 1.6.3+
Fix from $1,600 2021-08-31
Vault MEDIUM 5.3
CVE-2021-38554

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.…

Fix: 1.8.0+
Fix from $1,600 2021-08-13
Terraform HIGH 8.8
CVE-2021-36230

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the …

Fix: 202107-1+
Fix from $1,950 2021-07-20
Consul HIGH 7.5
CVE-2021-32574

HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod…

Fix: 1.8.14 / 1.9.8+
Fix from $1,950 2021-07-17
Consul HIGH 7.5
CVE-2021-36213

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out,…

Fix: 1.9.8 / 1.10.1+
Fix from $1,950 2021-07-17
Nomad MEDIUM 6.5
CVE-2021-32575

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed …

Fix: after 1.0.4
Fix from $1,600 2021-06-17
Vault HIGH 7.4
CVE-2021-32923

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 secon…

Fix: 1.5.9 / 1.6.5+
Fix from $1,950 2021-06-03
Vault Action HIGH 7.5
CVE-2021-32074

HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line se…

Fix: 2.2.0+
Fix from $1,950 2021-05-07
Terraform Provider CRITICAL 9.8
CVE-2021-30476

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed …

Fix: 2.19.1+
Fix from $2,300 2021-04-22
Vault HIGH 7.5
CVE-2021-27400

HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates wh…

Fix: 1.6.4 / 1.7.1+
Fix from $1,950 2021-04-22
Vault HIGH 7.5
CVE-2021-29653

HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed…

Fix: 1.5.8 / 1.6.4+
Fix from $1,950 2021-04-22