CVE-2025-6004
- EPSS 0.04%
- Veröffentlicht 01.08.2025 17:56:00
- Zuletzt bearbeitet 13.08.2025 18:10:19
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
CVE-2025-6037
- EPSS 0.06%
- Veröffentlicht 01.08.2025 17:52:48
- Zuletzt bearbeitet 13.08.2025 18:09:00
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]....
CVE-2025-6014
- EPSS 0.06%
- Veröffentlicht 01.08.2025 17:50:09
- Zuletzt bearbeitet 13.08.2025 18:09:14
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
CVE-2025-6000
- EPSS 0.24%
- Veröffentlicht 01.08.2025 17:40:48
- Zuletzt bearbeitet 13.08.2025 18:08:08
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Ent...
CVE-2025-5999
- EPSS 0.04%
- Veröffentlicht 01.08.2025 17:38:58
- Zuletzt bearbeitet 13.08.2025 18:08:26
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19...
CVE-2025-4656
- EPSS 0.11%
- Veröffentlicht 25.06.2025 16:15:11
- Zuletzt bearbeitet 13.08.2025 18:02:04
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and ...
CVE-2025-3879
- EPSS 0.23%
- Veröffentlicht 02.05.2025 16:15:10
- Zuletzt bearbeitet 12.08.2025 01:39:23
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Va...
CVE-2025-4166
- EPSS 0.15%
- Veröffentlicht 02.05.2025 14:57:58
- Zuletzt bearbeitet 31.12.2025 00:49:39
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. Th...
CVE-2024-8185
- EPSS 0.65%
- Veröffentlicht 31.10.2024 16:15:06
- Zuletzt bearbeitet 13.11.2025 17:40:36
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volu...
CVE-2024-9180
- EPSS 0.3%
- Veröffentlicht 10.10.2024 21:15:05
- Zuletzt bearbeitet 31.12.2025 00:49:50
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1....