İçeriğe atla
Noroxi

HashiCorp kayıtları

hashicorp üreticisine ait 194 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%85,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

194 kayıt
  • CVE-2021-41805
    45Planlayın

    HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.

    YüksekCVSS 8,8Kavram kanıtıEPSS %35

    hashicorp · consul12 Ara 2021

  • CVE-2020-29564
    41Planlayın

    The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.

    KritikCVSS 9,8İstismar yokEPSS %6

    hashicorp · consul docker image8 Ara 2020

  • CVE-2020-35192
    40Planlayın

    The official vault docker images before 0.11.6 contain a blank password for a root user.

    KritikCVSS 9,8İstismar yokEPSS %3

    hashicorp · vault16 Ara 2020

  • CVE-2019-12618
    40Planlayın

    HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.

    KritikCVSS 9,8İstismar yokEPSS %2

    hashicorp · nomad12 Ağu 2019

  • CVE-2018-9057
    40Planlayın

    aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriat

    KritikCVSS 9,8İstismar yokEPSS %2

    hashicorp · terraform27 Mar 2018

  • CVE-2022-26945
    40Planlayın

    go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response he

    KritikCVSS 9,8İstismar yokEPSS %2

    hashicorp · go-getter25 May 2022

  • CVE-2021-30476
    39İzleyin

    HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth metho

    KritikCVSS 9,8İstismar yokEPSS %2

    hashicorp · terraform provider22 Nis 2021

  • CVE-2020-12757
    39İzleyin

    HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials

    KritikCVSS 9,8İstismar yokEPSS %2

    hashicorp · vault10 Haz 2020

  • CVE-2022-30324
    39İzleyin

    HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation thro

    KritikCVSS 9,8İstismar yokEPSS %1

    hashicorp · nomad2 Haz 2022

  • CVE-2024-3817
    39İzleyin

    HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches

    KritikCVSS 9,8İstismar yokEPSS %1

    hashicorp · go-getter17 Nis 2024

  • CVE-2020-7956
    39İzleyin

    HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and

    KritikCVSS 9,8İstismar yokEPSS %1

    hashicorp · nomad31 Oca 2020

  • CVE-2023-1782
    39İzleyin

    Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation

    KritikCVSS 9,8İstismar yokEPSS %1

    hashicorp · nomad5 Nis 2023

  • CVE-2025-13357
    39İzleyin

    Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method

    KritikCVSS 9,8İstismar yokEPSS %1

    hashicorp · terraform provider21 Kas 2025

  • CVE-2022-36130
    39İzleyin

    HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scop

    KritikCVSS 9,9İstismar yokEPSS %0

    hashicorp · boundary31 Ağu 2022

  • CVE-2024-2048
    39İzleyin

    Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates

    KritikCVSS 9,8İstismar yokEPSS %0

    hashicorp · vault4 Mar 2024

  • CVE-2022-36129
    36İzleyin

    HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint

    KritikCVSS 9,1İstismar yokEPSS %2

    hashicorp · vault26 Tem 2022

  • CVE-2020-27195
    36İzleyin

    HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or ar

    KritikCVSS 9,1İstismar yokEPSS %1

    hashicorp · nomad22 Eki 2020

  • CVE-2020-10661
    36İzleyin

    HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies gran

    KritikCVSS 9,1İstismar yokEPSS %1

    hashicorp · vault23 Mar 2020

  • CVE-2022-40186
    36İzleyin

    An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.

    KritikCVSS 9,1İstismar yokEPSS %1

    hashicorp · vault21 Eyl 2022

  • CVE-2025-6000
    36İzleyin

    Arbitrary Remote Code Execution via Plugin Catalog Abuse

    KritikCVSS 9,1İstismar yokEPSS %1

    hashicorp · vault1 Ağu 2025

  • CVE-2025-0377
    36İzleyin

    HashiCorp go-slug Vulnerable to Zip Slip Attack

    KritikCVSS 9,1İstismar yokEPSS %1

    hashicorp · go-slug21 Oca 2025

  • CVE-2021-3121
    35İzleyin

    An issue was discovered in GoGo Protobuf before 1.3.2.

    YüksekCVSS 8,6İstismar yokEPSS %3

    golang · protobuf11 Oca 2021

  • CVE-2022-30321
    35İzleyin

    go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws

    YüksekCVSS 8,6İstismar yokEPSS %3

    hashicorp · go-getter25 May 2022

  • CVE-2021-43415
    35İzleyin

    HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job

    YüksekCVSS 8,8İstismar yokEPSS %1

    hashicorp · nomad3 Ara 2021

  • CVE-2021-37219
    35İzleyin

    HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to acce

    YüksekCVSS 8,8İstismar yokEPSS %1

    hashicorp · consul7 Eyl 2021