Show filters
167 Total Results
Displaying 81-90 of 167
Sort by:
Attacker Value
Unknown

CVE-2022-25244

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Attacker Value
Unknown

CVE-2022-25243

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
Attacker Value
Unknown

CVE-2022-24685

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
Attacker Value
Unknown

CVE-2022-25374

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
Attacker Value
Unknown

CVE-2022-24687

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.
Attacker Value
Unknown

CVE-2022-24683

Disclosure Date: February 17, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
Attacker Value
Unknown

CVE-2022-24684

Disclosure Date: February 15, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.
Attacker Value
Unknown

CVE-2022-24686

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
Attacker Value
Unknown

CVE-2021-45042

Disclosure Date: December 17, 2021 (last updated October 07, 2023)
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
Attacker Value
Unknown

CVE-2021-41805

Disclosure Date: December 12, 2021 (last updated February 23, 2025)
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.