VYPR
Vendor

Hashicorp

Products
32
CVEs
222
Across products
323
Status
Private

Products

32
View all 32 products →

Recent CVEs

222
View all 222 CVEs →
  • CVE-2023-1782CriApr 5, 2023
    risk 0.64cvss 9.9epss 0.01

    HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

  • CVE-2022-36130CriSep 1, 2022
    risk 0.64cvss 9.9epss 0.00

    HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.

  • CVE-2022-30324CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

  • CVE-2021-30476CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.02

    HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

  • CVE-2020-35192CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-29564CriDec 8, 2020
    risk 0.64cvss 9.8epss 0.06

    The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2019-12618CriAug 12, 2019
    risk 0.64cvss 9.8epss 0.02

    HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.

  • CVE-2021-41805HigDec 12, 2021
    risk 0.60cvss 8.8epss 0.35

    HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

  • CVE-2017-11741HigAug 8, 2017
    risk 0.60cvss 8.8epss 0.01

    HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.

  • CVE-2025-6000CriAug 1, 2025
    risk 0.59cvss 9.1epss 0.01

    A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7,…

  • CVE-2022-40186CriSep 22, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an…

  • CVE-2022-36129CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.02

    HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or…

  • CVE-2024-3817CriApr 17, 2024
    risk 0.57cvss 9.8epss 0.01

    HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

  • CVE-2023-2816HigJun 2, 2023
    risk 0.57cvss 8.7epss 0.01

    Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s)…

  • CVE-2022-26945CriMay 25, 2022
    risk 0.57cvss 9.8epss 0.02

    go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

  • CVE-2021-43415HigDec 3, 2021
    risk 0.57cvss 8.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

  • CVE-2021-40862HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.

  • CVE-2021-37218HigSep 7, 2021
    risk 0.57cvss 8.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

  • CVE-2021-36230HigJul 20, 2021
    risk 0.57cvss 8.8epss 0.01

    HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

  • CVE-2020-12757CriJun 10, 2020
    risk 0.57cvss 9.8epss 0.02

    HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being…