HashiCorp kayıtları
hashicorp üreticisine ait 194 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %85,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-266 Incorrect Privilege Assignment12
- CWE-295 Improper Certificate Validation11
- CWE-532 Insertion of Sensitive Information into Log File11
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-863 Incorrect Authorization9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
194 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2021-41805Kavram kanıtı | HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.hashicorp · consul · CWE-863 | Yüksek8,8 | — | %34,8 | 12 Ara 2021 |
41Planlayın | CVE-2020-29564İstismar yok | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.hashicorp · consul docker image | Kritik9,8 | — | %6,2 | 8 Ara 2020 |
40Planlayın | CVE-2020-35192İstismar yok | The official vault docker images before 0.11.6 contain a blank password for a root user.hashicorp · vault · CWE-306 | Kritik9,8 | — | %2,9 | 16 Ara 2020 |
40Planlayın | CVE-2019-12618İstismar yok | HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.hashicorp · nomad · CWE-269 | Kritik9,8 | — | %2,4 | 12 Ağu 2019 |
40Planlayın | CVE-2018-9057İstismar yok | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriathashicorp · terraform · CWE-332 | Kritik9,8 | — | %1,9 | 27 Mar 2018 |
40Planlayın | CVE-2022-26945İstismar yok | go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response hehashicorp · go-getter | Kritik9,8 | — | %1,7 | 25 May 2022 |
39İzleyin | CVE-2021-30476İstismar yok | HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth methohashicorp · terraform provider | Kritik9,8 | — | %1,6 | 22 Nis 2021 |
39İzleyin | CVE-2020-12757İstismar yok | HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials hashicorp · vault · CWE-269 | Kritik9,8 | — | %1,5 | 10 Haz 2020 |
39İzleyin | CVE-2022-30324İstismar yok | HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation throhashicorp · nomad | Kritik9,8 | — | %1,4 | 2 Haz 2022 |
39İzleyin | CVE-2024-3817İstismar yok | HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Brancheshashicorp · go-getter · CWE-88 | Kritik9,8 | — | %1,3 | 17 Nis 2024 |
39İzleyin | CVE-2020-7956İstismar yok | HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and hashicorp · nomad · CWE-295 | Kritik9,8 | — | %1,0 | 31 Oca 2020 |
39İzleyin | CVE-2023-1782İstismar yok | Nomad Unauthenticated Client Agent HTTP Request Privilege Escalationhashicorp · nomad · CWE-862 | Kritik9,8 | — | %0,8 | 5 Nis 2023 |
39İzleyin | CVE-2025-13357İstismar yok | Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Methodhashicorp · terraform provider · CWE-1188 | Kritik9,8 | — | %0,5 | 21 Kas 2025 |
39İzleyin | CVE-2022-36130İstismar yok | HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scophashicorp · boundary · CWE-345 | Kritik9,9 | — | %0,5 | 31 Ağu 2022 |
39İzleyin | CVE-2024-2048İstismar yok | Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificateshashicorp · vault · CWE-295 | Kritik9,8 | — | %0,4 | 4 Mar 2024 |
36İzleyin | CVE-2022-36129İstismar yok | HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint hashicorp · vault · CWE-306 | Kritik9,1 | — | %1,6 | 26 Tem 2022 |
36İzleyin | CVE-2020-27195İstismar yok | HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or arhashicorp · nomad | Kritik9,1 | — | %1,5 | 22 Eki 2020 |
36İzleyin | CVE-2020-10661İstismar yok | HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies granhashicorp · vault | Kritik9,1 | — | %1,1 | 23 Mar 2020 |
36İzleyin | CVE-2022-40186İstismar yok | An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.hashicorp · vault · CWE-639 | Kritik9,1 | — | %1,0 | 21 Eyl 2022 |
36İzleyin | CVE-2025-6000İstismar yok | Arbitrary Remote Code Execution via Plugin Catalog Abusehashicorp · vault · CWE-94 | Kritik9,1 | — | %0,9 | 1 Ağu 2025 |
36İzleyin | CVE-2025-0377İstismar yok | HashiCorp go-slug Vulnerable to Zip Slip Attackhashicorp · go-slug · CWE-59 | Kritik9,1 | — | %0,7 | 21 Oca 2025 |
35İzleyin | CVE-2021-3121İstismar yok | An issue was discovered in GoGo Protobuf before 1.3.2.golang · protobuf · CWE-129 | Yüksek8,6 | — | %3,5 | 11 Oca 2021 |
35İzleyin | CVE-2022-30321İstismar yok | go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flawshashicorp · go-getter · CWE-22 | Yüksek8,6 | — | %3,3 | 25 May 2022 |
35İzleyin | CVE-2021-43415İstismar yok | HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with jobhashicorp · nomad | Yüksek8,8 | — | %1,2 | 3 Ara 2021 |
35İzleyin | CVE-2021-37219İstismar yok | HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to accehashicorp · consul · CWE-295 | Yüksek8,8 | — | %1,1 | 7 Eyl 2021 |
- CVE-2021-4180545Planlayın
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.
YüksekCVSS 8,8Kavram kanıtıEPSS %35hashicorp · consul12 Ara 2021
- CVE-2020-2956441Planlayın
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %6hashicorp · consul docker image8 Ara 2020
- CVE-2020-3519240Planlayın
The official vault docker images before 0.11.6 contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %3hashicorp · vault16 Ara 2020
- CVE-2019-1261840Planlayın
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · nomad12 Ağu 2019
- CVE-2018-905740Planlayın
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriat
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · terraform27 Mar 2018
- CVE-2022-2694540Planlayın
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response he
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · go-getter25 May 2022
- CVE-2021-3047639İzleyin
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth metho
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · terraform provider22 Nis 2021
- CVE-2020-1275739İzleyin
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · vault10 Haz 2020
- CVE-2022-3032439İzleyin
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation thro
KritikCVSS 9,8İstismar yokEPSS %1hashicorp · nomad2 Haz 2022
- CVE-2024-381739İzleyin
HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches
KritikCVSS 9,8İstismar yokEPSS %1hashicorp · go-getter17 Nis 2024
- CVE-2020-795639İzleyin
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and
KritikCVSS 9,8İstismar yokEPSS %1hashicorp · nomad31 Oca 2020
- CVE-2023-178239İzleyin
Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation
KritikCVSS 9,8İstismar yokEPSS %1hashicorp · nomad5 Nis 2023
- CVE-2025-1335739İzleyin
Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method
KritikCVSS 9,8İstismar yokEPSS %1hashicorp · terraform provider21 Kas 2025
- CVE-2022-3613039İzleyin
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scop
KritikCVSS 9,9İstismar yokEPSS %0hashicorp · boundary31 Ağu 2022
- CVE-2024-204839İzleyin
Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates
KritikCVSS 9,8İstismar yokEPSS %0hashicorp · vault4 Mar 2024
- CVE-2022-3612936İzleyin
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint
KritikCVSS 9,1İstismar yokEPSS %2hashicorp · vault26 Tem 2022
- CVE-2020-2719536İzleyin
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or ar
KritikCVSS 9,1İstismar yokEPSS %1hashicorp · nomad22 Eki 2020
- CVE-2020-1066136İzleyin
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies gran
KritikCVSS 9,1İstismar yokEPSS %1hashicorp · vault23 Mar 2020
- CVE-2022-4018636İzleyin
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3.
KritikCVSS 9,1İstismar yokEPSS %1hashicorp · vault21 Eyl 2022
- CVE-2025-600036İzleyin
Arbitrary Remote Code Execution via Plugin Catalog Abuse
KritikCVSS 9,1İstismar yokEPSS %1hashicorp · vault1 Ağu 2025
- CVE-2025-037736İzleyin
HashiCorp go-slug Vulnerable to Zip Slip Attack
KritikCVSS 9,1İstismar yokEPSS %1hashicorp · go-slug21 Oca 2025
- CVE-2021-312135İzleyin
An issue was discovered in GoGo Protobuf before 1.3.2.
YüksekCVSS 8,6İstismar yokEPSS %3golang · protobuf11 Oca 2021
- CVE-2022-3032135İzleyin
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws
YüksekCVSS 8,6İstismar yokEPSS %3hashicorp · go-getter25 May 2022
- CVE-2021-4341535İzleyin
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job
YüksekCVSS 8,8İstismar yokEPSS %1hashicorp · nomad3 Ara 2021
- CVE-2021-3721935İzleyin
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to acce
YüksekCVSS 8,8İstismar yokEPSS %1hashicorp · consul7 Eyl 2021