hashicorp

201 tracked vulnerabilities.

CVE-2021-42135 HIGH
HashiCorp Vault 1.8.0-1.8.4 - Improper Privilege Management via Glob Policy Interaction
Oct 11, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-41802 LOW
HashiCorp Vault < 1.7.5 - Privilege Escalation via Entity Alias Merging
Oct 08, 2021
CVSS 2.9
EPSS 0.00
CVE-2021-41865 MEDIUM
Nomad 1.1.1-1.1.5 - Authenticated Denial of Service via Incomplete Job Specification with Consul Mesh Gateway
Oct 07, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-40862 HIGH
HashiCorp Terraform Enterprise <202109-1 - Info Disclosure
Sep 15, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-38698 MEDIUM
HashiCorp Consul < 1.8.15, 1.10.1 - Missing Authorization in Txn.Apply Endpoint
Sep 07, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-37219 HIGH
HashiCorp Consul <1.8.15, 1.10.1 - Privilege Escalation via Raft RPC Layer
Sep 07, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-37218 HIGH
HashiCorp Nomad < 1.0.10 - Privilege Escalation via Raft RPC Layer
Sep 07, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-27668 MEDIUM
HashiCorp Vault Enterprise <1.6.2 - Info Disclosure
Aug 31, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-38554 MEDIUM
HashiCorp Vault <1.8.0 - Info Disclosure
Aug 13, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-38553 MEDIUM
HashiCorp Vault <1.8.0 - Info Disclosure
Aug 13, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-36230 HIGH
HashiCorp Terraform Enterprise <v202107-1 - Privilege Escalation
Jul 20, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-36213 HIGH
HashiCorp Consul <1.9.8-1.10.1 - DoS
Jul 17, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-32574 HIGH
HashiCorp Consul 1.3.0-1.10.0 - Improper Certificate Validation in Envoy Proxy TLS Configuration
Jul 17, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-32575 MEDIUM
HashiCorp Nomad <1.0.4 - Privilege Escalation
Jun 17, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-32923 HIGH
HashiCorp Vault <1.5.9, <1.6.5, <1.7.2 - Info Disclosure
Jun 03, 2021
CVSS 7.4
EPSS 0.00
CVE-2021-32074 HIGH
HashiCorp vault-action < 2.2.0 - Sensitive Information Exposure via Multi-Line Secret Log Masking Bypass
May 07, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-30476 CRITICAL
HashiCorp Terraform's Vault Provider - Auth Bypass
Apr 22, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-29653 HIGH
HashiCorp Vault 1.5.1-1.5.7 - Improper Certificate Validation in PKI Engine CRL Generation
Apr 22, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-27400 HIGH
HashiCorp Vault <1.6.4, <1.7.1 - Info Disclosure
Apr 22, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-28156 HIGH
HashiCorp Consul Enterprise <1.9.4 - Auth Bypass
Apr 20, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-3153 MEDIUM
HashiCorp Terraform Enterprise < 202102-2 - Improper Authentication via Organization-Level MFA Bypass
Mar 26, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-3283 HIGH
HashiCorp Nomad <0.12.9 - Privilege Escalation
Feb 01, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-3282 HIGH
HashiCorp Vault Enterprise <1.6.2 - Privilege Escalation
Feb 01, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-3024 MEDIUM
HashiCorp Vault <1.6.2-1.5.7 - Info Disclosure
Feb 01, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-3121 HIGH
GoGo Protobuf < 1.3.2 - Denial of Service via Improper Array Index Validation
Jan 11, 2021
CVSS 8.6
EPSS 0.00