Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-44139EPSS 6% Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). Sentinel No fix yet Fix from $1,9502022-03-23 MEDIUM 6.5 CVE-2022-25243 "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates… Vault 1.8.9 / 1.9.4+ Fix from $1,6002022-03-10 MEDIUM 6.5 CVE-2022-25244 Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoin… Vault 1.7.10 / 1.8.9+ Fix from $1,6002022-03-10 HIGH 7.5 CVE-2022-24685 HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fi… Nomad 1.1.12 / 1.2.6+ Fix from $1,9502022-02-28 HIGH 7.5 CVE-2022-25374 HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may captu… Terraform Enterprise 202202-1+ Fix from $1,9502022-02-25 MEDIUM 6.5 CVE-2022-24687 HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:… Consul 1.9.15 / 1.10.8+ Fix from $1,6002022-02-24 HIGH 7.5 CVE-2022-24683 HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities… Nomad 1.0.18 / 1.1.12+ Fix from $1,9502022-02-17 MEDIUM 6.5 CVE-2022-24684 HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to… Nomad 1.0.18 / 1.1.12+ Fix from $1,6002022-02-15 MEDIUM 5.9 CVE-2022-24686 HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad… Nomad 1.0.18 / 1.1.12+ Fix from $1,6002022-02-14 HIGH 8.8 CVE-2021-41805EPSS 35% HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default… Consul 1.8.17 / 1.9.11+ Fix from $1,9502021-12-12 HIGH 8.8 CVE-2021-43415 HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submissi… Nomad 1.0.14 / 1.1.8+ Fix from $1,9502021-12-03 MEDIUM 6.5 CVE-2021-43998 HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multipl… Vault after 1.7.5 Fix from $1,6002021-11-30 HIGH 8.1 CVE-2021-42135 HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secret… Vault after 1.8.4 Fix from $1,9502021-10-11 MEDIUM 5.4 CVE-2021-41802 HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with… Vault 1.7.5 / 1.8.4+ Fix from $1,6002021-10-08 MEDIUM 6.5 CVE-2021-41865 HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by s… Nomad 1.1.6+ Fix from $1,6002021-10-07 HIGH 8.8 CVE-2021-40862 HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which c… Terraform Enterprise after 202108-1 Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-37218 HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only fun… Nomad 1.0.10 / 1.1.4+ Fix from $1,9502021-09-07 HIGH 8.8 CVE-2021-37219 HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server… Consul 1.8.15 / 1.9.9+ Fix from $1,9502021-09-07 MEDIUM 6.5 CVE-2021-38698 HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service … Consul 1.8.15 / 1.9.9+ Fix from $1,6002021-09-07 MEDIUM 5.3 CVE-2021-27668 HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3. Vault 1.6.3+ Fix from $1,6002021-08-31 MEDIUM 5.3 CVE-2021-38554 HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.… Vault 1.8.0+ Fix from $1,6002021-08-13 HIGH 8.8 CVE-2021-36230 HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the … Terraform 202107-1+ Fix from $1,9502021-07-20 HIGH 7.5 CVE-2021-32574 HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod… Consul 1.8.14 / 1.9.8+ Fix from $1,9502021-07-17 HIGH 7.5 CVE-2021-36213 HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out,… Consul 1.9.8 / 1.10.1+ Fix from $1,9502021-07-17 MEDIUM 6.5 CVE-2021-32575 HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed … Nomad after 1.0.4 Fix from $1,6002021-06-17 HIGH 7.4 CVE-2021-32923 HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 secon… Vault 1.5.9 / 1.6.5+ Fix from $1,9502021-06-03 HIGH 7.5 CVE-2021-32074 HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line se… Vault Action 2.2.0+ Fix from $1,9502021-05-07 CRITICAL 9.8 CVE-2021-30476 HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed … Terraform Provider 2.19.1+ Fix from $2,3002021-04-22 HIGH 7.5 CVE-2021-27400 HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates wh… Vault 1.6.4 / 1.7.1+ Fix from $1,9502021-04-22 HIGH 7.5 CVE-2021-29653 HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed… Vault 1.5.8 / 1.6.4+ Fix from $1,9502021-04-22