Show filters
188 Total Results
Displaying 61-70 of 188
Sort by:
Attacker Value
Unknown
CVE-2022-36129
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
0
Attacker Value
Unknown
CVE-2017-20086
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
0
Attacker Value
Unknown
CVE-2022-30689
Disclosure Date: May 17, 2022 (last updated October 07, 2023)
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
0
Attacker Value
Unknown
CVE-2021-27779
Disclosure Date: April 30, 2022 (last updated February 23, 2025)
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
0
Attacker Value
Unknown
CVE-2022-25244
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
0
Attacker Value
Unknown
CVE-2022-25243
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
0
Attacker Value
Unknown
CVE-2022-25197
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-25186
Disclosure Date: February 15, 2022 (last updated October 07, 2023)
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.
0
Attacker Value
Unknown
CVE-2022-23109
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
0
Attacker Value
Unknown
CVE-2021-36751
Disclosure Date: January 02, 2022 (last updated February 23, 2025)
ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.
0