Show filters
167 Total Results
Displaying 71-80 of 167
Sort by:
Attacker Value
Unknown

CVE-2022-36129

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
Attacker Value
Unknown

CVE-2022-30324

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
Attacker Value
Unknown

CVE-2022-26945

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30323

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30321

Disclosure Date: May 25, 2022 (last updated February 23, 2025)
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30322

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30689

Disclosure Date: May 17, 2022 (last updated October 07, 2023)
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
Attacker Value
Unknown

CVE-2022-29810

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
Attacker Value
Unknown

CVE-2022-29153

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
Attacker Value
Unknown

CVE-2021-44139

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).