Hashicorp Vault vulnerabilities

72 known vulnerabilities affecting hashicorp/vault.

Total CVEs
72
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH28MEDIUM34LOW3

Vulnerabilities

Page 3 of 4
CVE-2023-24999HIGHCVSS 8.1fixed in 1.10.11≥ 1.11.0, < 1.11.8+1 more2023-03-11
CVE-2023-24999 [HIGH] CWE-863 CVE-2023-24999: HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with acces HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
nvd
CVE-2022-41316MEDIUMCVSS 5.3fixed in 1.9.10≥ 1.10.0, < 1.10.7+1 more2022-10-12
CVE-2022-41316 [MEDIUM] CWE-295 CVE-2022-41316: HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the option HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
nvd
CVE-2022-40186CRITICALCVSS 9.1≥ 1.8.0, < 1.9.9≥ 1.10.0, < 1.10.6+1 more2022-09-22
CVE-2022-40186 [CRITICAL] CWE-639 CVE-2022-40186: An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in th An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may a
nvd
CVE-2022-36129CRITICALCVSS 9.1≥ 1.7.0, ≤ 1.9.7≥ 1.10.0, ≤ 1.10.4+1 more2022-07-26
CVE-2022-36129 [CRITICAL] CWE-306 CVE-2022-36129: HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
nvd
CVE-2022-30689MEDIUMCVSS 5.3≥ 1.10.0, < 1.10.32022-05-17
CVE-2022-30689 [MEDIUM] CVE-2022-30689: HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce M HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
nvd
CVE-2022-25244MEDIUMCVSS 6.5≥ 1.7.0, < 1.7.10≥ 1.8.0, < 1.8.9+1 more2022-03-10
CVE-2022-25244 [MEDIUM] CVE-2022-25244: Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key t Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
nvd
CVE-2022-25243MEDIUMCVSS 6.5≥ 1.8.0, < 1.8.9≥ 1.9.0, < 1.9.42022-03-10
CVE-2022-25243 [MEDIUM] CWE-295 CVE-2022-25243: "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under cert "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
nvd
CVE-2021-45042MEDIUMCVSS 4.9≥ 1.4.0, < 1.7.7≥ 1.8.0, < 1.8.6+1 more2021-12-17
CVE-2021-45042 [MEDIUM] CVE-2021-45042: In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, cl In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
nvd
CVE-2021-43998MEDIUMCVSS 6.5≥ 0.11.0, ≤ 1.7.5v1.8.42021-11-30
CVE-2021-43998 [MEDIUM] CWE-732 CVE-2021-43998: HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would alway HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
nvd
CVE-2021-42135HIGHCVSS 8.1≥ 1.8.0, ≤ 1.8.42021-10-11
CVE-2021-42135 [HIGH] CWE-269 CVE-2021-42135: HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
nvd
CVE-2021-41802MEDIUMCVSS 5.4fixed in 1.7.5≥ 1.8.0, < 1.8.42021-10-08
CVE-2021-41802 [MEDIUM] CWE-732 CVE-2021-41802: HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
nvd
CVE-2021-27668MEDIUMCVSS 5.3≥ 0.9.2, < 1.6.32021-08-31
CVE-2021-27668 [MEDIUM] CWE-306 CVE-2021-27668: HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondar HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
nvd
CVE-2021-38554MEDIUMCVSS 5.3fixed in 1.8.02021-08-13
CVE-2021-38554 [MEDIUM] CWE-212 CVE-2021-38554: HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
nvd
CVE-2021-38553MEDIUMCVSS 4.4≥ 1.4.0, < 1.8.02021-08-13
CVE-2021-38553 [MEDIUM] CWE-281 CVE-2021-38553: HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file ass HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
nvd
CVE-2021-32923HIGHCVSS 7.4≥ 0.10.0, < 1.5.9≥ 1.6.0, < 1.6.5+1 more2021-06-03
CVE-2021-32923 [HIGH] CWE-613 CVE-2021-32923: HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
nvd
CVE-2021-27400HIGHCVSS 7.5fixed in 1.6.4≥ 1.7.0, < 1.7.12021-04-22
CVE-2021-27400 [HIGH] CWE-295 CVE-2021-27400: HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets en HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
nvd
CVE-2021-29653HIGHCVSS 7.5≥ 1.5.1, < 1.5.8≥ 1.6.0, < 1.6.4+1 more2021-04-22
CVE-2021-29653 [HIGH] CWE-295 CVE-2021-29653: HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revok HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
nvd
CVE-2021-3282HIGHCVSS 7.5v1.6.0v1.6.12021-02-01
CVE-2021-3282 [HIGH] CWE-287 CVE-2021-3282: HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be execu HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
nvd
CVE-2020-25594MEDIUMCVSS 5.3fixed in 1.5.7≥ 1.6.0, < 1.6.22021-02-01
CVE-2020-25594 [MEDIUM] CVE-2020-25594: HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unaut HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
nvd
CVE-2021-3024MEDIUMCVSS 5.3fixed in 1.5.7≥ 1.6.0, < 1.6.22021-02-01
CVE-2021-3024 [MEDIUM] CVE-2021-3024: HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when respon HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
nvd
Hashicorp Vault vulnerabilities | cvebase