Github.Com Hashicorp Vault vulnerabilities

55 known vulnerabilities affecting github.com/hashicorp_vault.

Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH24MEDIUM22LOW3

Vulnerabilities

Page 2 of 3
CVE-2024-7594HIGH≥ 1.7.7, < 1.17.62024-09-26
CVE-2024-7594 [HIGH] CWE-732 Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to aut
ghsaosv
CVE-2024-8365MEDIUMCVSS 6.5≥ 1.17.3, < 1.17.52024-09-02
CVE-2024-8365 [MEDIUM] CWE-532 Vault Leaks Client Token and Token Accessor in Audit Devices Vault Leaks Client Token and Token Accessor in Audit Devices Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-202
ghsaosv
CVE-2024-6468HIGH≥ 1.10.0, < 1.15.12≥ 1.16.0-rc1, < 1.16.3+1 more2024-07-11
CVE-2024-6468 [HIGH] CWE-703 Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When receiving a request from a source IP address that was not listed in proxy_protocol_authorized_addrs, the Vault
ghsaosv
CVE-2024-5798HIGHCVSS 7.5≥ 1.17.0-rc1, < 1.17.0≥ 1.16.0-rc1, < 1.16.3+1 more2024-06-12
CVE-2024-5798 [HIGH] CWE-285 HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected. This
ghsaosv
CVE-2024-2660MEDIUM≥ 0, < 1.16.02024-04-04
CVE-2024-2660 [MEDIUM] CWE-636 HashiCorpVault does not correctly validate OCSP responses HashiCorpVault does not correctly validate OCSP responses Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
ghsaosv
CVE-2024-2048HIGH≥ 1.15.0, < 1.15.5≥ 0, < 1.14.102024-03-04
CVE-2024-2048 [HIGH] CWE-295 Incorrect TLS certificate auth method in Vault Incorrect TLS certificate auth method in Vault Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
ghsaosv
CVE-2024-0831MEDIUM≥ 1.15.0, < 1.15.52024-02-01
CVE-2024-0831 [MEDIUM] CWE-532 Hashicorp Vault may expose sensitive log information Hashicorp Vault may expose sensitive log information Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`
ghsaosv
CVE-2020-16251HIGH≥ 0.8.3, < 1.2.5≥ 1.3.0, < 1.3.8+2 more2024-01-31
CVE-2020-16251 [HIGH] CWE-287 HashiCorp Vault Authentication bypass HashiCorp Vault Authentication bypass HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
ghsaosv
CVE-2021-3282HIGH≥ 1.6.0, < 1.6.22024-01-31
CVE-2021-3282 [HIGH] CWE-287 Improper Authentication in HashiCorp Vault Improper Authentication in HashiCorp Vault HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
ghsaosv
CVE-2020-35177MEDIUM≥ 1.5.0, < 1.5.6≥ 1.6.0, < 1.6.12024-01-31
CVE-2020-35177 [MEDIUM] CWE-200 Enumeration of users in HashiCorp Vault Enumeration of users in HashiCorp Vault HashiCorp Vault and Vault Enterprise allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
ghsaosv
CVE-2020-10661CRITICAL≥ 0.11.0, < 1.3.42024-01-30
CVE-2020-10661 [CRITICAL] CWE-269 HashiCorp Vault Improper Privilege Management HashiCorp Vault Improper Privilege Management HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.
ghsaosv
CVE-2020-10660MEDIUM≥ 0.9.0, < 1.3.42024-01-30
CVE-2020-10660 [MEDIUM] CWE-269 HashiCorp Vault Improper Privilege Management HashiCorp Vault Improper Privilege Management HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
ghsaosv
CVE-2023-6337HIGH≥ 1.15.0, < 1.15.4≥ 1.14.0, < 1.14.8+1 more2023-12-09
CVE-2023-6337 [HIGH] CWE-770 Memory exhaustion in HashiCorp Vault Memory exhaustion in HashiCorp Vault HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash. Fixed in Vault 1.15.4, 1.14.8, 1.13.12.
ghsaosv
CVE-2023-5954HIGH≥ 0, < 1.13.10≥ 1.14.0, < 1.14.6+1 more2023-11-09
CVE-2023-5954 [HIGH] CWE-401 HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
ghsaosv
CVE-2023-5077HIGH≥ 0, < 1.13.02023-09-29
CVE-2023-5077 [HIGH] CWE-266 Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
ghsaosv
CVE-2023-4680MEDIUM≥ 1.6.0, < 1.12.11≥ 1.13.0, < 1.13.7+1 more2023-09-15
CVE-2023-4680 [MEDIUM] CWE-20 HashiCorp Vault Improper Input Validation vulnerability HashiCorp Vault Improper Input Validation vulnerability HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without con
ghsaosv
CVE-2023-3462MEDIUM≥ 0, < 1.13.5≥ 1.14.0, < 1.14.12023-08-01
CVE-2023-3462 [MEDIUM] CWE-203 HashiCorp Vault and Vault Enterprise vulnerable to user enumeration HashiCorp Vault and Vault Enterprise vulnerable to user enumeration HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
ghsaosv
CVE-2023-24999HIGHCVSS 8.1≥ 0, < 1.10.11≥ 1.11.0, < 1.11.8+1 more2023-07-06
CVE-2023-24999 [HIGH] Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation When using the Vault and Vault Enterprise (Vault) approle auth method, any authenticated user with access to the `/auth/approle/role/:role_name/secret-id-accessor/destroy` endpoint can destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability, CVE-2
ghsaosv
CVE-2022-41316MEDIUM≥ 1.11.0, < 1.11.4≥ 1.10.0, < 1.10.7+1 more2023-07-06
CVE-2022-41316 [MEDIUM] CWE-295 HashiCorp Vault's revocation list not respected HashiCorp Vault's revocation list not respected HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
ghsaosv
CVE-2023-2121MEDIUMCVSS 5.4≥ 0, < 1.11.11≥ 1.12.0, < 1.12.7+1 more2023-06-09
CVE-2023-2121 [MEDIUM] CWE-79 Hashicorp Vault vulnerable to Cross-site Scripting Hashicorp Vault vulnerable to Cross-site Scripting Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.
ghsaosv
Github.Com Hashicorp Vault vulnerabilities | cvebase