Show filters
167 Total Results
Displaying 81-90 of 167
Sort by:
Attacker Value
Unknown
CVE-2022-25244
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
0
Attacker Value
Unknown
CVE-2022-25243
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
0
Attacker Value
Unknown
CVE-2022-24685
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
0
Attacker Value
Unknown
CVE-2022-25374
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
0
Attacker Value
Unknown
CVE-2022-24687
Disclosure Date: February 24, 2022 (last updated October 07, 2023)
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.
0
Attacker Value
Unknown
CVE-2022-24683
Disclosure Date: February 17, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
0
Attacker Value
Unknown
CVE-2022-24684
Disclosure Date: February 15, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.
0
Attacker Value
Unknown
CVE-2022-24686
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
0
Attacker Value
Unknown
CVE-2021-45042
Disclosure Date: December 17, 2021 (last updated October 07, 2023)
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
0
Attacker Value
Unknown
CVE-2021-41805
Disclosure Date: December 12, 2021 (last updated February 23, 2025)
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
0