Vulnerability index

Browse CVEs

174 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-19879 HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2. Sentinel after 0.10.1 Fix from $1,9502020-02-14 CRITICAL 9.8 CVE-2020-7956 HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susc… Nomad 0.10.3+ Fix from $2,3002020-01-31 HIGH 7.5 CVE-2020-7218 HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial … Nomad 0.10.3+ Fix from $1,9502020-01-31 HIGH 7.5 CVE-2020-7219 HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial… Consul 1.6.2+ Fix from $1,9502020-01-31 MEDIUM 5.3 CVE-2020-7955 HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended… Consul 1.6.2+ Fix from $1,6002020-01-31 HIGH 7.5 CVE-2020-7220 HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed … Vault 1.3.2+ Fix from $1,9502020-01-23 HIGH 7.5 CVE-2019-19316 When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot usin… Terraform 0.12.17+ Fix from $1,9502019-12-02 CRITICAL 9.8 CVE-2019-12618 HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver. Nomad after 0.9.1 Fix from $2,3002019-08-12 HIGH 7.5 CVE-2019-12291 HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be … Consul after 1.5.0 Fix from $1,9502019-06-06 HIGH 7.4 CVE-2019-9764 HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_serv… Consul No fix yet Fix from $1,9502019-03-26 HIGH 8.1 CVE-2019-8336 HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one o… Consul 1.4.3+ Fix from $1,9502019-03-05 MEDIUM 5.9 CVE-2018-19653 HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented.… Consul after 1.4.0 Fix from $1,6002018-12-09 HIGH 8.1 CVE-2018-19786 HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from… Vault 1.0.0+ Fix from $1,9502018-12-05 MEDIUM 5.3 CVE-2018-15869 An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validati… Packer 1.3.0+ Fix from $1,6002018-08-25 HIGH 7.8 CVE-2017-16512 The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update re… Vagrant Vmware Fusion after 5.0.4 Fix from $1,9502018-03-29 HIGH 7.8 CVE-2017-16873 It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to r… Vagrant Vmware Fusion after 5.0.4 Fix from $1,9502018-03-29 HIGH 7.0 CVE-2017-16839 Hashicorp vagrant-vmware-fusion 5.0.4 allows local users to steal root privileges if VMware Fusion is not installed. Vagrant Vmware Fusion No fix yet Fix from $1,9502018-03-29 CRITICAL 9.8 CVE-2018-9057 aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG al… Terraform after 1.12.0 Fix from $2,3002018-03-27 HIGH 7.8 CVE-2017-16777 If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake… Vagrant No fix yet Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-16001 In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update proce… Vagrant No fix yet Fix from $1,9502017-11-06 HIGH 7.0 CVE-2017-15884 In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update proce… Vagrant Vmware Fusion No fix yet Fix from $1,9502017-10-31 HIGH 7.8 CVE-2017-12579 An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user t… Vagrant Vmware Fusion after 4.0.24 Fix from $1,9502017-10-19 HIGH 8.8 CVE-2017-11741 HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local user… Vagrant Vmware Fusion after 4.0.23 Fix from $1,9502017-08-08 HIGH 7.8 CVE-2017-7642 The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by… Vagrant Vmware Fusion after 4.0.20 Fix from $1,9502017-08-02