|
HCSEC-2021-08 - Consul Enterprise Audit Log Bypass for HTTP Events
|
|
0
|
7639
|
April 19, 2021
|
|
HCSEC-2022-04 - Nomad Spread Job Stanza May Trigger Panic in Servers
|
|
0
|
7602
|
February 11, 2022
|
|
HCSEC-2022-01 - Nomad Artifact Download Race Condition
|
|
0
|
7544
|
February 11, 2022
|
|
HCSEC-2023-31 - Vagrant’s Windows Installer Allowed Directory Junction Write
|
|
0
|
7536
|
October 27, 2023
|
|
HCSEC-2021-06 - Terraform Enterprise Organization-Level MFA Requirement Was Not Enforced
|
|
0
|
7525
|
March 23, 2021
|
|
HCSEC-2021-05 - Vault Enterprise’s DR Secondaries Exposed License Metadata Without Authentication
|
|
0
|
7494
|
February 26, 2021
|
|
HCSEC-2021-18 - Terraform Enterprise Allowed Privilege Escalation Via Run Token
|
|
0
|
7486
|
July 20, 2021
|
|
HCSEC-2023-12 - Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
|
|
0
|
7477
|
March 30, 2023
|
|
HCSEC-2023-26 - Terraform’s Handling Of Duplicate Map Keys In Configurations May Have Security Implications
|
|
0
|
7424
|
August 24, 2023
|
|
HCSEC-2022-05 - Consul Ingress Gateway Panic Can Shutdown Servers
|
|
0
|
7407
|
February 15, 2022
|
|
HCSEC-2021-01 - Nomad’s Exec and Java Task Drivers Did Not Isolate Processes
|
|
0
|
7382
|
January 29, 2021
|
|
HCSEC-2021-28 - Vault's Google Cloud Secrets Engine Policies With Globs May Provide Additional Privileges in Vault 1.8.0 Onwards
|
|
0
|
7380
|
October 7, 2021
|
|
HCSEC-2021-25 - Terraform Enterprise Configuration Versions API Discloses Sensitive URL
|
|
0
|
7363
|
September 14, 2021
|
|
HCSEC-2020-24 - Vault Enterprise’s Sentinel EGP Policies May Impact Parent or Sibling Namespaces
|
|
0
|
7347
|
December 16, 2020
|
|
HCSEC-2022-02 - Nomad alloc Filesystem and Container Escape
|
|
0
|
7313
|
February 11, 2022
|
|
HCSEC-2022-19 - Consul Auto-Config JWT Authorization Missing Input Validation
|
|
0
|
7285
|
September 21, 2022
|
|
HCSEC-2022-08 - Vault Enterprise’s Tokenization Transform Configuration Endpoint May Expose Transform Key
|
|
0
|
7260
|
March 4, 2022
|
|
HCSEC-2022-03 - Nomad Malformed Job Parsing Results in Excessive CPU Usage
|
|
0
|
7231
|
February 11, 2022
|
|
HCSEC-2021-31 - Nomad QEMU Task Driver Allowed Paths Bypass with Job Args
|
|
0
|
7178
|
November 23, 2021
|
|
HCSEC-2021-33 - Vault’s KV Secrets Engine With Integrated Storage Exposed to Authenticated Denial of Service
|
|
0
|
7123
|
December 14, 2021
|
|
HCSEC-2022-24 - Vault's TLS Cert Auth Method Only Loaded CRL After First Request
|
|
0
|
7059
|
October 12, 2022
|
|
HCSEC-2025-11 Vault Vulnerable to Recovery Key Cancellation Denial of Service
|
|
0
|
1241
|
June 25, 2025
|
|
HCSEC-2022-14 - Nomad Impacted by go-getter Vulnerabilities
|
|
0
|
6950
|
May 24, 2022
|
|
HCSEC-2023-17 - Vault’s KV Diff Viewer Allowed HTML Injection
|
|
0
|
6933
|
June 9, 2023
|
|
HCSEC-2021-21 - Nomad Raft RPC Privilege Escalation
|
|
0
|
6903
|
September 1, 2021
|
|
HCSEC-2023-07 - Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
|
|
0
|
6801
|
March 10, 2023
|
|
HCSEC-2023-04 - go-getter vulnerable to denial of service via malicious compressed archive
|
|
0
|
6794
|
February 13, 2023
|
|
HCSEC-2021-26 - Nomad Denial Of Service Via Submission Of Incomplete Job Specification Using Consul Mesh Gateway & Host Network
|
|
0
|
6606
|
October 5, 2021
|
|
HCSEC-2024-01 - Vault May Expose Sensitive Information When Configuring An Audit Log Device
|
|
0
|
6599
|
February 1, 2024
|
|
HCSEC-2023-15 - Consul Cluster Peering can Result in Denial of Service
|
|
0
|
6592
|
June 2, 2023
|
|
HCSEC-2024-03 - Nomad Vulnerable to Arbitrary Write Through Symlink Attack
|
|
0
|
6555
|
February 8, 2024
|
|
HCSEC-2020-20 - Vault Leases Created with Batch Tokens have Invalid Expiration
|
|
1
|
4561
|
September 2, 2021
|
|
HCSEC-2023-11 - Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata
|
|
0
|
6398
|
March 30, 2023
|
|
HCSEC-2022-28 - Consul Cluster Peering Leaks Imported Nodes/Services Information
|
|
0
|
6388
|
November 15, 2022
|
|
HCSEC-2022-23 - Vagrant NFS sudoers Configuration Allows for Local Privilege Escalation
|
|
0
|
6316
|
October 10, 2022
|
|
HCSEC-2022-17 - Boundary Allowed Access To Host Sets And Credential Sources For Authorized Users Of Another Scope
|
|
0
|
6281
|
August 23, 2022
|
|
HCSEC-2023-16 - Consul Envoy Extension Downstream Proxy Configuration By Upstream Service Owner
|
|
0
|
6265
|
June 2, 2023
|
|
HCSEC-2023-18 - Terraform Enterprise Agent Pool Controls Allowed Unauthorized Workspaces to Target an Agent Pool
|
|
0
|
6193
|
June 22, 2023
|
|
HCSEC-2023-14 - Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-Based Encryption Mechanism with a HSM
|
|
0
|
6129
|
May 1, 2023
|
|
HCSEC-2023-13 - Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation
|
|
0
|
6128
|
April 5, 2023
|
|
HCSEC-2022-25 - Nomad’s Workload Identity Token Can List Non-sensitive Metadata For nomad/ Paths
|
|
0
|
5995
|
October 28, 2022
|
|
HCSEC-2022-26 - Nomad’s Event Stream Subscriber Using ACL Token with TTL Receive Updates Until Garbage Collected
|
|
0
|
5937
|
October 28, 2022
|
|
HCSEC-2022-22 - Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
|
|
0
|
5891
|
October 10, 2022
|
|
HCSEC-2023-20 - Nomad ACL Policies without Label are Applied to Unexpected Resources
|
|
0
|
5885
|
July 19, 2023
|
|
HCSEC-2024-02 - Boundary Vulnerable to Session Hijacking Through TLS Certificate Tampering
|
|
0
|
5859
|
February 5, 2024
|
|
HCSEC-2023-22 - Nomad Search API Leaks Information About CSI Plugins
|
|
0
|
5823
|
July 19, 2023
|
|
HCSEC-2025-22 - Multiple Vulnerabilities Impacting HashiCorp Vault and Vault Enterprise
|
|
0
|
5775
|
August 6, 2025
|
|
HCSEC-2023-21 - Nomad Caller ACL Token's Secret ID is Exposed to Sentinel
|
|
0
|
5682
|
July 19, 2023
|
|
HCSEC-2024-07 - Vault TLS Cert Auth Method Did Not Correctly Validate OCSP Responses
|
|
0
|
5426
|
April 4, 2024
|
|
HCSEC-2023-02 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Go’s net/http (CVE-2022-41717)
|
|
0
|
5369
|
February 8, 2023
|