Записи HashiCorp
194 опубликованных записей вендора hashicorp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-266 Incorrect Privilege Assignment12
- CWE-295 Improper Certificate Validation11
- CWE-532 Insertion of Sensitive Information into Log File11
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-863 Incorrect Authorization9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
194 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2021-41805Proof of concept | HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.hashicorp · consul · CWE-863 | Высокая8,8 | — | 34,8 % | 12 дек. 2021 г. |
41В плане | CVE-2020-29564Эксплойта нет | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.hashicorp · consul docker image | Критическая9,8 | — | 6,2 % | 8 дек. 2020 г. |
40В плане | CVE-2020-35192Эксплойта нет | The official vault docker images before 0.11.6 contain a blank password for a root user.hashicorp · vault · CWE-306 | Критическая9,8 | — | 2,9 % | 16 дек. 2020 г. |
40В плане | CVE-2019-12618Эксплойта нет | HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.hashicorp · nomad · CWE-269 | Критическая9,8 | — | 2,4 % | 12 авг. 2019 г. |
40В плане | CVE-2018-9057Эксплойта нет | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriathashicorp · terraform · CWE-332 | Критическая9,8 | — | 1,9 % | 27 мар. 2018 г. |
40В плане | CVE-2022-26945Эксплойта нет | go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response hehashicorp · go-getter | Критическая9,8 | — | 1,7 % | 25 мая 2022 г. |
39Наблюдать | CVE-2021-30476Эксплойта нет | HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth methohashicorp · terraform provider | Критическая9,8 | — | 1,6 % | 22 апр. 2021 г. |
39Наблюдать | CVE-2020-12757Эксплойта нет | HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials hashicorp · vault · CWE-269 | Критическая9,8 | — | 1,5 % | 10 июн. 2020 г. |
39Наблюдать | CVE-2022-30324Эксплойта нет | HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation throhashicorp · nomad | Критическая9,8 | — | 1,4 % | 2 июн. 2022 г. |
39Наблюдать | CVE-2024-3817Эксплойта нет | HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Brancheshashicorp · go-getter · CWE-88 | Критическая9,8 | — | 1,3 % | 17 апр. 2024 г. |
39Наблюдать | CVE-2020-7956Эксплойта нет | HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and hashicorp · nomad · CWE-295 | Критическая9,8 | — | 1,0 % | 31 янв. 2020 г. |
39Наблюдать | CVE-2023-1782Эксплойта нет | Nomad Unauthenticated Client Agent HTTP Request Privilege Escalationhashicorp · nomad · CWE-862 | Критическая9,8 | — | 0,8 % | 5 апр. 2023 г. |
39Наблюдать | CVE-2025-13357Эксплойта нет | Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Methodhashicorp · terraform provider · CWE-1188 | Критическая9,8 | — | 0,5 % | 21 нояб. 2025 г. |
39Наблюдать | CVE-2022-36130Эксплойта нет | HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scophashicorp · boundary · CWE-345 | Критическая9,9 | — | 0,5 % | 31 авг. 2022 г. |
39Наблюдать | CVE-2024-2048Эксплойта нет | Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificateshashicorp · vault · CWE-295 | Критическая9,8 | — | 0,4 % | 4 мар. 2024 г. |
36Наблюдать | CVE-2022-36129Эксплойта нет | HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint hashicorp · vault · CWE-306 | Критическая9,1 | — | 1,6 % | 26 июл. 2022 г. |
36Наблюдать | CVE-2020-27195Эксплойта нет | HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or arhashicorp · nomad | Критическая9,1 | — | 1,5 % | 22 окт. 2020 г. |
36Наблюдать | CVE-2020-10661Эксплойта нет | HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies granhashicorp · vault | Критическая9,1 | — | 1,1 % | 23 мар. 2020 г. |
36Наблюдать | CVE-2022-40186Эксплойта нет | An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.hashicorp · vault · CWE-639 | Критическая9,1 | — | 1,0 % | 21 сент. 2022 г. |
36Наблюдать | CVE-2025-6000Эксплойта нет | Arbitrary Remote Code Execution via Plugin Catalog Abusehashicorp · vault · CWE-94 | Критическая9,1 | — | 0,9 % | 1 авг. 2025 г. |
36Наблюдать | CVE-2025-0377Эксплойта нет | HashiCorp go-slug Vulnerable to Zip Slip Attackhashicorp · go-slug · CWE-59 | Критическая9,1 | — | 0,7 % | 21 янв. 2025 г. |
35Наблюдать | CVE-2021-3121Эксплойта нет | An issue was discovered in GoGo Protobuf before 1.3.2.golang · protobuf · CWE-129 | Высокая8,6 | — | 3,5 % | 11 янв. 2021 г. |
35Наблюдать | CVE-2022-30321Эксплойта нет | go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flawshashicorp · go-getter · CWE-22 | Высокая8,6 | — | 3,3 % | 25 мая 2022 г. |
35Наблюдать | CVE-2021-43415Эксплойта нет | HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with jobhashicorp · nomad | Высокая8,8 | — | 1,2 % | 3 дек. 2021 г. |
35Наблюдать | CVE-2021-37219Эксплойта нет | HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to accehashicorp · consul · CWE-295 | Высокая8,8 | — | 1,1 % | 7 сент. 2021 г. |
- CVE-2021-4180545В плане
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.
ВысокаяCVSS 8,8Proof of conceptEPSS 35 %hashicorp · consul12 дек. 2021 г.
- CVE-2020-2956441В плане
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %hashicorp · consul docker image8 дек. 2020 г.
- CVE-2020-3519240В плане
The official vault docker images before 0.11.6 contain a blank password for a root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hashicorp · vault16 дек. 2020 г.
- CVE-2019-1261840В плане
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · nomad12 авг. 2019 г.
- CVE-2018-905740В плане
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriat
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · terraform27 мар. 2018 г.
- CVE-2022-2694540В плане
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response he
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · go-getter25 мая 2022 г.
- CVE-2021-3047639Наблюдать
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth metho
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · terraform provider22 апр. 2021 г.
- CVE-2020-1275739Наблюдать
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · vault10 июн. 2020 г.
- CVE-2022-3032439Наблюдать
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation thro
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hashicorp · nomad2 июн. 2022 г.
- CVE-2024-381739Наблюдать
HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hashicorp · go-getter17 апр. 2024 г.
- CVE-2020-795639Наблюдать
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hashicorp · nomad31 янв. 2020 г.
- CVE-2023-178239Наблюдать
Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hashicorp · nomad5 апр. 2023 г.
- CVE-2025-1335739Наблюдать
Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hashicorp · terraform provider21 нояб. 2025 г.
- CVE-2022-3613039Наблюдать
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scop
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %hashicorp · boundary31 авг. 2022 г.
- CVE-2024-204839Наблюдать
Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hashicorp · vault4 мар. 2024 г.
- CVE-2022-3612936Наблюдать
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %hashicorp · vault26 июл. 2022 г.
- CVE-2020-2719536Наблюдать
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or ar
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hashicorp · nomad22 окт. 2020 г.
- CVE-2020-1066136Наблюдать
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies gran
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hashicorp · vault23 мар. 2020 г.
- CVE-2022-4018636Наблюдать
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hashicorp · vault21 сент. 2022 г.
- CVE-2025-600036Наблюдать
Arbitrary Remote Code Execution via Plugin Catalog Abuse
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hashicorp · vault1 авг. 2025 г.
- CVE-2025-037736Наблюдать
HashiCorp go-slug Vulnerable to Zip Slip Attack
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hashicorp · go-slug21 янв. 2025 г.
- CVE-2021-312135Наблюдать
An issue was discovered in GoGo Protobuf before 1.3.2.
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %golang · protobuf11 янв. 2021 г.
- CVE-2022-3032135Наблюдать
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %hashicorp · go-getter25 мая 2022 г.
- CVE-2021-4341535Наблюдать
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hashicorp · nomad3 дек. 2021 г.
- CVE-2021-3721935Наблюдать
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to acce
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hashicorp · consul7 сент. 2021 г.