Show filters
167 Total Results
Displaying 71-80 of 167
Sort by:
Attacker Value
Unknown
CVE-2022-36129
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
0
Attacker Value
Unknown
CVE-2022-30324
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
0
Attacker Value
Unknown
CVE-2022-26945
Disclosure Date: May 25, 2022 (last updated October 07, 2023)
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
0
Attacker Value
Unknown
CVE-2022-30323
Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
0
Attacker Value
Unknown
CVE-2022-30321
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
0
Attacker Value
Unknown
CVE-2022-30322
Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
0
Attacker Value
Unknown
CVE-2022-30689
Disclosure Date: May 17, 2022 (last updated October 07, 2023)
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
0
Attacker Value
Unknown
CVE-2022-29810
Disclosure Date: April 27, 2022 (last updated February 23, 2025)
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
0
Attacker Value
Unknown
CVE-2022-29153
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
0
Attacker Value
Unknown
CVE-2021-44139
Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
0