VYPR

Vault

by Hashicorp

Source repositories

CVEs (74)

  • CVE-2023-5954MedNov 9, 2023
    risk 0.38cvss 5.9epss 0.01

    HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

  • CVE-2025-6015MedAug 1, 2025
    risk 0.37cvss 5.7epss 0.00

    Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

  • CVE-2024-2877MedApr 30, 2024
    risk 0.36cvss 5.5epss 0.00

    Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed…

  • CVE-2023-0620MedMar 30, 2023
    risk 0.35cvss 6.5epss 0.00

    HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed…

  • CVE-2021-27668MedAug 31, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.

  • CVE-2021-38554MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

  • CVE-2021-3024MedFeb 1, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

  • CVE-2020-25594MedFeb 1, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

  • CVE-2020-35453MedDec 17, 2020
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.

  • CVE-2025-6004MedAug 1, 2025
    risk 0.34cvss 5.3epss 0.00

    Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

  • CVE-2023-3462MedJul 31, 2023
    risk 0.34cvss 5.3epss 0.01

    HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This…

  • CVE-2022-41316MedOct 12, 2022
    risk 0.34cvss 5.3epss 0.00

    HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0,…

  • CVE-2024-8365MedSep 2, 2024
    risk 0.33cvss 6.2epss 0.00

    Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token…

  • CVE-2023-3774MedJul 28, 2023
    risk 0.32cvss 4.9epss 0.01

    An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.

  • CVE-2021-45042MedDec 17, 2021
    risk 0.32cvss 4.9epss 0.01

    In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage…

  • CVE-2023-24999MedMar 11, 2023
    risk 0.29cvss 4.4epss 0.01

    HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8,…

  • CVE-2021-38553MedAug 13, 2021
    risk 0.29cvss 4.4epss 0.00

    HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

  • CVE-2023-2121MedJun 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

  • CVE-2022-30689MedMay 17, 2022
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set.…

  • CVE-2020-10660MedMar 23, 2020
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.