Loading HuntDB...

hashicorp

17 Products 55 CVEs

CVE Severity Distribution (All Time)

Critical
2
High
17
Medium
30
Low
6

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 14 CVEs

Recent CVEs

View all
CVE-2024-12678 MEDIUM 6 months, 2 weeks ago

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload iden…

CVE-2024-12289 MEDIUM 6 months, 3 weeks ago

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller…

CVE-2024-10975 HIGH 7 months, 3 weeks ago

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized C…

CVE-2024-8185 HIGH 8 months ago

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack t…

CVE-2024-10086 MEDIUM 8 months ago

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allow…

CVE-2024-10006 HIGH 8 months ago

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header b…

CVE-2024-10005 HIGH 8 months ago

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP reques…

CVE-2024-10228 LOW 8 months ago

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, int…

CVE-2024-9180 HIGH 8 months, 3 weeks ago

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to…

CVE-2024-7594 HIGH 9 months, 1 week ago

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields o…