CVE-2021-32923
- EPSS 0.65%
- Veröffentlicht 03.06.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:56
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequen...
CVE-2021-29653
- EPSS 0.1%
- Veröffentlicht 22.04.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:34
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
CVE-2021-27400
- EPSS 0.24%
- Veröffentlicht 22.04.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:57:55
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
CVE-2021-3282
- EPSS 0.32%
- Veröffentlicht 01.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:12
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
CVE-2021-3024
- EPSS 0.48%
- Veröffentlicht 01.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 06:20:46
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
CVE-2020-25594
- EPSS 0.48%
- Veröffentlicht 01.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:11
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
CVE-2020-35453
- EPSS 0.33%
- Veröffentlicht 17.12.2020 05:15:10
- Zuletzt bearbeitet 21.11.2024 05:27:18
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.
CVE-2020-35177
- EPSS 0.4%
- Veröffentlicht 17.12.2020 05:15:10
- Zuletzt bearbeitet 21.11.2024 05:26:54
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
- EPSS 2.01%
- Veröffentlicht 17.12.2020 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:26:55
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank passwor...
CVE-2020-25816
- EPSS 0.44%
- Veröffentlicht 30.09.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:18:49
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.