Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Consul HIGH 7.5
CVE-2021-28156

HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.

Fix: 1.8.10 / 1.9.5+
Fix from $1,950 2021-04-20
Consul MEDIUM 6.1
CVE-2020-25864EPSS 6%

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and…

Fix: 1.7.14 / 1.8.10+
Fix from $1,600 2021-04-20
Terraform Enterprise MEDIUM 6.5
CVE-2021-3153

HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two…

Fix: after 202102-2
Fix from $1,600 2021-03-26
Vault HIGH 7.5
CVE-2021-3282

HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication…

Mitigation only
Fix from $1,950 2021-02-01
Nomad HIGH 7.5
CVE-2021-3283

HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed…

Fix: 0.12.10 / 1.0.3+
Fix from $1,950 2021-02-01
Vault MEDIUM 5.3
CVE-2021-3024

HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP reques…

Fix: 1.5.7 / 1.6.2+
Fix from $1,600 2021-02-01
Vault MEDIUM 5.3
CVE-2020-25594

HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

Fix: 1.5.7 / 1.6.2+
Fix from $1,600 2021-02-01
Vault MEDIUM 5.3
CVE-2020-35177

HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.

Fix: 1.5.6 / 1.6.1+
Fix from $1,600 2020-12-17
Vault MEDIUM 5.3
CVE-2020-35453

HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.…

Fix: 1.5.6 / 1.6.1+
Fix from $1,600 2020-12-17
Vault CRITICAL 9.8
CVE-2020-35192

The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected…

Fix: 0.11.6+
Fix from $2,300 2020-12-17
Consul Docker Image CRITICAL 9.8
CVE-2020-29564EPSS 6%

The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by …

Fix: after 1.4.2
Fix from $2,300 2020-12-08
Go Slug HIGH 7.5
CVE-2020-29529

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with …

Fix: 0.5.0+
Fix from $1,950 2020-12-03
Nomad MEDIUM 6.5
CVE-2020-28348

HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when usin…

Fix: 0.10.8 / 0.11.7+
Fix from $1,600 2020-11-24
Consul MEDIUM 6.5
CVE-2020-28053

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key conf…

Fix: 1.6.10 / 1.7.10+
Fix from $1,600 2020-11-23
Consul HIGH 7.5
CVE-2020-25201

HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infi…

Fix: after 1.8.4
Fix from $1,950 2020-11-04
Nomad CRITICAL 9.1
CVE-2020-27195

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact st…

Fix: after 0.12.5
Fix from $2,300 2020-10-22
Vault MEDIUM 6.8
CVE-2020-25816

HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time wa…

Fix: 1.4.7 / 1.5.4+
Fix from $1,600 2020-09-30
Vault HIGH 8.2
CVE-2020-16250

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypa…

Fix: 1.2.5 / 1.3.8+
Fix from $1,950 2020-08-26
Vault HIGH 8.2
CVE-2020-16251

HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypa…

Fix: 1.2.5 / 1.3.8+
Fix from $1,950 2020-08-26
Vault Ssh Helper HIGH 7.5
CVE-2020-24359

HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network inte…

Fix: 0.2.0+
Fix from $1,950 2020-08-20
Terraform Enterprise MEDIUM 5.3
CVE-2020-15511

HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enfo…

Fix: 202007-1+
Fix from $1,600 2020-07-30
Consul HIGH 7.5
CVE-2020-12758

HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.…

Fix: 1.6.6 / 1.7.4+
Fix from $1,950 2020-06-11
Consul HIGH 7.5
CVE-2020-13170

HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a s…

Fix: 1.6.6 / 1.7.4+
Fix from $1,950 2020-06-11
Consul HIGH 7.5
CVE-2020-13250

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to…

Fix: 1.6.6 / 1.7.4+
Fix from $1,950 2020-06-11
Consul MEDIUM 5.3
CVE-2020-12797

HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduc…

Fix: 1.6.6 / 1.7.4+
Fix from $1,600 2020-06-11
Vault CRITICAL 9.8
CVE-2020-12757

HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the …

Fix: 1.4.2+
Fix from $2,300 2020-06-10
Vault HIGH 7.5
CVE-2020-13223

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

Fix: 1.3.6 / 1.4.2+
Fix from $1,950 2020-06-10
Nomad MEDIUM 5.4
CVE-2020-10944

HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could caus…

Fix: 0.10.5+
Fix from $1,600 2020-04-28
Vault CRITICAL 9.1
CVE-2020-10661

HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access …

Fix: after 1.3.3
Fix from $2,300 2020-03-23
Vault MEDIUM 5.3
CVE-2020-10660

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently i…

Fix: after 1.3.3
Fix from $1,600 2020-03-23