← Back

Hashicorp

hashicorp

193 CVEs • 21 products

Products (21)

Click to collapse
Toggle
Vault
vault
Nomad
nomad
Consul
consul
Go Getter
go-getter
Terraform
terraform
Boundary
boundary
Vagrant
vagrant
Sentinel
sentinel
Go Slug
go-slug
Packer
packer
Vault Action
vault-action
Retryablehttp
retryablehttp
Hermes
hermes

CVEs (193)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Vault
Jun 17, 2026
May 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 an...Show more
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.Show less
1Hashicorp
1Go Getter
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
2Fedoraproject
Hashicorp
2Consul
Fedora
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10....Show more
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.Show less
1Hashicorp
1Sentinel
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
1Hashicorp
1Vault
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fix...Show more
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.Show less
1Hashicorp
1Vault
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role polic...Show more
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Feb 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
1Hashicorp
1Terraform Enterprise
Jun 17, 2026
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
1Hashicorp
1Consul
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul...Show more
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Feb 17, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
1Hashicorp
1Nomad
Jun 17, 2026
Feb 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.
1Hashicorp
1Nomad
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destinat...Show more
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6Show less
1Hashicorp
1Vault
Jun 17, 2026
Dec 17, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine...Show more
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.Show less
1Hashicorp
1Consul
Jun 17, 2026
Dec 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintende...Show more
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Dec 3, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in...Show more
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.Show less
1Hashicorp
1Vault
Jun 17, 2026
Nov 30, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, po...Show more
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.Show less
1Hashicorp
1Vault
Jun 17, 2026
Oct 11, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than inte...Show more
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.Show less
1Hashicorp
1Vault
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their id...Show more
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.Show less