Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2024-10228
Disclosure Date: October 29, 2024 (last updated November 08, 2024)
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
0
Attacker Value
Unknown
CVE-2023-5834
Disclosure Date: October 27, 2023 (last updated November 14, 2023)
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
0
Attacker Value
Unknown
CVE-2022-25962
Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
0
Attacker Value
Unknown
CVE-2022-42717
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.
0
Attacker Value
Unknown
CVE-2021-21361
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.
0
Attacker Value
Unknown
CVE-2017-16839
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
Hashicorp vagrant-vmware-fusion 5.0.4 allows local users to steal root privileges if VMware Fusion is not installed.
0
Attacker Value
Unknown
CVE-2017-16512
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.
0
Attacker Value
Unknown
CVE-2017-16873
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.
0
Attacker Value
Unknown
CVE-2017-16777
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.
0
Attacker Value
Unknown
CVE-2017-16001
Disclosure Date: November 06, 2017 (last updated November 26, 2024)
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
0