← Back

Hashicorp

hashicorp

193 CVEs • 21 products

Products (21)

Click to collapse
Toggle
Vault
vault
Nomad
nomad
Consul
consul
Go Getter
go-getter
Terraform
terraform
Boundary
boundary
Vagrant
vagrant
Sentinel
sentinel
Go Slug
go-slug
Packer
packer
Vault Action
vault-action
Retryablehttp
retryablehttp
Hermes
hermes

CVEs (193)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Nomad
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and...Show more
HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.Show less
1Hashicorp
1Terraform Enterprise
Jun 17, 2026
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a...Show more
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.Show less
1Hashicorp
1Consul
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
1Hashicorp
1Consul
Jun 17, 2026
Sep 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1....Show more
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Sep 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.
1Hashicorp
1Vault
Jun 17, 2026
Aug 31, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
1Hashicorp
1Vault
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
1Hashicorp
1Vault
Jun 17, 2026
Aug 13, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Ente...Show more
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.Show less
1Hashicorp
1Terraform
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed i...Show more
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.Show less
1Hashicorp
1Consul
Jun 17, 2026
Jul 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. F...Show more
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.Show less
1Hashicorp
1Consul
Jun 17, 2026
Jul 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.
1Hashicorp
1Nomad
Jun 17, 2026
Jun 17, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.
1Hashicorp
1Vault
Jun 17, 2026
Jun 3, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as...Show more
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.Show less
1Hashicorp
1Vault Action
Jun 17, 2026
May 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
1Hashicorp
1Terraform Provider
Jun 17, 2026
Apr 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
1Hashicorp
1Vault
Jun 17, 2026
Apr 22, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
1Hashicorp
1Vault
Jun 17, 2026
Apr 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
1Hashicorp
1Consul
Jun 17, 2026
Apr 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
1Hashicorp
1Consul
Jun 17, 2026
Apr 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
1Hashicorp
1Terraform Enterprise
Jun 17, 2026
Mar 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.