Show filters
167 Total Results
Displaying 51-60 of 167
Sort by:
Attacker Value
Unknown
CVE-2023-1299
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.
0
Attacker Value
Unknown
CVE-2023-1296
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
0
Attacker Value
Unknown
CVE-2023-24999
Disclosure Date: March 11, 2023 (last updated October 08, 2023)
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
0
Attacker Value
Unknown
CVE-2023-0845
Disclosure Date: March 09, 2023 (last updated October 08, 2023)
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.
0
Attacker Value
Unknown
CVE-2023-0821
Disclosure Date: February 16, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
0
Attacker Value
Unknown
CVE-2023-0475
Disclosure Date: February 16, 2023 (last updated October 08, 2023)
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
0
Attacker Value
Unknown
CVE-2023-0690
Disclosure Date: February 08, 2023 (last updated November 08, 2023)
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This would result in the credentials being stored in plaintext on the Boundary PKI worker’s disk.
This issue is fixed in version 0.12.0.
0
Attacker Value
Unknown
CVE-2019-14802
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
0
Attacker Value
Unknown
CVE-2022-3920
Disclosure Date: November 16, 2022 (last updated December 22, 2024)
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
0
Attacker Value
Unknown
CVE-2022-3866
Disclosure Date: November 10, 2022 (last updated December 22, 2024)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
0