Show filters
188 Total Results
Displaying 51-60 of 188
Sort by:
Attacker Value
Unknown

CVE-2023-20859

Disclosure Date: March 23, 2023 (last updated October 08, 2023)
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
Attacker Value
Unknown

CVE-2022-47171

Disclosure Date: March 14, 2023 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul C. Schroeder IP Vault – WP Firewall plugin <= 1.1 versions.
Attacker Value
Unknown

CVE-2023-24999

Disclosure Date: March 11, 2023 (last updated October 08, 2023)
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
Attacker Value
Unknown

CVE-2023-23691

Disclosure Date: January 20, 2023 (last updated November 08, 2023)
Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize its connection with the website, typically leading to XSS and DoS.
Attacker Value
Unknown

CVE-2022-47581

Disclosure Date: December 21, 2022 (last updated October 08, 2023)
Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
Attacker Value
Unknown

CVE-2022-41316

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Attacker Value
Unknown

CVE-2022-40186

Disclosure Date: September 22, 2022 (last updated November 29, 2024)
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
Attacker Value
Unknown

CVE-2022-27560

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
HCL VersionVault Express exposes administrator credentials.
Attacker Value
Unknown

CVE-2022-27563

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
Attacker Value
Unknown

CVE-2022-36888

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.