About HashiCorp security updates
|
|
0
|
6377
|
October 8, 2020
|
HCSEC-2023-28 - Vault’s Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption
|
|
0
|
838
|
September 14, 2023
|
HCSEC-2023-27 - Terraform Allows Arbitrary File Write During Init Operation
|
|
0
|
1523
|
September 8, 2023
|
HCSEC-2023-26 - Terraform’s Handling Of Duplicate Map Keys In Configurations May Have Security Implications
|
|
0
|
618
|
August 24, 2023
|
HCSEC-2023-25 - Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
|
|
0
|
1244
|
August 8, 2023
|
HCSEC-2023-24 - Vault's LDAP Auth Method Allows for User Enumeration
|
|
0
|
1478
|
July 31, 2023
|
HCSEC-2023-23 - Vault Enterprise Namespace Creation May Lead to Denial of Service
|
|
0
|
1480
|
July 28, 2023
|
HCSEC-2023-22 - Nomad Search API Leaks Information About CSI Plugins
|
|
0
|
1044
|
July 19, 2023
|
HCSEC-2023-21 - Nomad Caller ACL Token's Secret ID is Exposed to Sentinel
|
|
0
|
1006
|
July 19, 2023
|
HCSEC-2023-20 - Nomad ACL Policies without Label are Applied to Unexpected Resources
|
|
0
|
1059
|
July 19, 2023
|
HCSEC-2023-19 - Terraform Enterprise, Docker Engine, and Go’s CVE-2023-24540
|
|
1
|
2660
|
June 28, 2023
|
HCSEC-2023-18 - Terraform Enterprise Agent Pool Controls Allowed Unauthorized Workspaces to Target an Agent Pool
|
|
0
|
1656
|
June 22, 2023
|
HCSEC-2023-17 - Vault’s KV Diff Viewer Allowed HTML Injection
|
|
0
|
2085
|
June 9, 2023
|
HCSEC-2023-16 - Consul Envoy Extension Downstream Proxy Configuration By Upstream Service Owner
|
|
0
|
1685
|
June 2, 2023
|
HCSEC-2023-15 - Consul Cluster Peering can Result in Denial of Service
|
|
0
|
1744
|
June 2, 2023
|
HCSEC-2023-14 - Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-Based Encryption Mechanism with a HSM
|
|
0
|
2019
|
May 1, 2023
|
HCSEC-2023-13 - Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation
|
|
0
|
2331
|
April 5, 2023
|
HCSEC-2023-12 - Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
|
|
0
|
3182
|
March 30, 2023
|
HCSEC-2023-11 - Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata
|
|
0
|
2339
|
March 30, 2023
|
HCSEC-2023-10 - Vault Vulnerable to Cache-Timing Attacks During Seal and Unseal Operations
|
|
0
|
3213
|
March 30, 2023
|
HCSEC-2023-09 - Nomad ACLs Can Not Deny Access to Workload's Own Variables
|
|
0
|
1936
|
March 13, 2023
|
HCSEC-2023-08 - Nomad Job Submitter Privilege Escalation Using Workload Identity
|
|
0
|
1919
|
March 13, 2023
|
HCSEC-2023-07 - Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
|
|
0
|
2963
|
March 10, 2023
|
HCSEC-2023-06 - Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
|
|
0
|
2408
|
March 9, 2023
|
HCSEC-2023-05 - Nomad Client Vulnerable to Decompression Bombs in Artifact Block
|
|
0
|
2194
|
February 16, 2023
|
HCSEC-2023-04 - go-getter vulnerable to denial of service via malicious compressed archive
|
|
0
|
3068
|
February 13, 2023
|
HCSEC-2023-03 - Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
|
|
0
|
2156
|
February 8, 2023
|
HCSEC-2023-02 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Go’s net/http (CVE-2022-41717)
|
|
0
|
2108
|
February 8, 2023
|
HCSEC-2023-01 - HashiCorp Response to CircleCI Security Alert
|
|
3
|
10650
|
April 24, 2023
|
HCSEC-2022-28 - Consul Cluster Peering Leaks Imported Nodes/Services Information
|
|
0
|
2982
|
November 15, 2022
|