HCSEC-2025-09 - Vault May Expose Sensitive Information in Error Logs When Processing Malformed Data With the KV v2 Plugin
|
|
0
|
181
|
May 2, 2025
|
HCSEC-2025-07 - Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login
|
|
0
|
139
|
May 2, 2025
|
HCSEC-2024-26 - Vault Vulnerable to Denial of Service Through Memory Exhaustion When Processing Raft Cluster Join Requests
|
|
0
|
1257
|
October 31, 2024
|
HCSEC-2024-21 - Vault Operators in Root Namespace May Elevate Their Privileges
|
|
0
|
2706
|
October 10, 2024
|
HCSEC-2024-20 - Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
|
|
0
|
2078
|
September 26, 2024
|
HCSEC-2024-18 - Vault Leaks Client Token and Token Accessor in Audit Devices
|
|
0
|
2653
|
August 31, 2024
|
HCSEC-2024-14 - Vault Vulnerable to Denial of Service When Setting a Proxy Protocol Behavior
|
|
0
|
1953
|
July 11, 2024
|
HCSEC-2024-11 - Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
|
|
0
|
3506
|
June 12, 2024
|
HCSEC-2024-10 - Vault Enterprise Leaks Sensitive HTTP Request Headers in Audit Log When Deployed With a Performance Standby Node
|
|
0
|
3906
|
April 30, 2024
|
HCSEC-2024-07 - Vault TLS Cert Auth Method Did Not Correctly Validate OCSP Responses
|
|
0
|
5110
|
April 4, 2024
|
HCSEC-2024-05 - Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates
|
|
0
|
9503
|
March 4, 2024
|
HCSEC-2024-01 - Vault May Expose Sensitive Information When Configuring An Audit Log Device
|
|
0
|
6389
|
February 1, 2024
|
HCSEC-2023-34 - Vault Vulnerable to Denial of Service Through Memory Exhaustion When Handling Large HTTP Requests
|
|
0
|
9365
|
December 8, 2023
|
HCSEC-2023-33 - Vault Requests Triggering Policy Checks May Lead To Unbounded Memory Consumption
|
|
0
|
7851
|
November 9, 2023
|
HCSEC-2023-32 - Vault, Consul, and Boundary Affected By HTTP/2 “Rapid Reset” Denial of Service Vulnerability (CVE-2023-44487)
|
|
0
|
13215
|
November 2, 2023
|
HCSEC-2023-30 - Vault’s Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets
|
|
0
|
7829
|
September 28, 2023
|
HCSEC-2023-29 - Vault Enterprise’s Sentinel RGP Policies Allowed For Cross-Namespace Denial of Service
|
|
0
|
7912
|
September 28, 2023
|
HCSEC-2023-28 - Vault’s Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption
|
|
0
|
8376
|
September 14, 2023
|
HCSEC-2023-24 - Vault's LDAP Auth Method Allows for User Enumeration
|
|
0
|
8285
|
July 31, 2023
|
HCSEC-2023-23 - Vault Enterprise Namespace Creation May Lead to Denial of Service
|
|
0
|
7946
|
July 28, 2023
|
HCSEC-2023-17 - Vault’s KV Diff Viewer Allowed HTML Injection
|
|
0
|
6779
|
June 9, 2023
|
HCSEC-2023-14 - Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-Based Encryption Mechanism with a HSM
|
|
0
|
6064
|
May 1, 2023
|
HCSEC-2023-12 - Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
|
|
0
|
7380
|
March 30, 2023
|
HCSEC-2023-11 - Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata
|
|
0
|
6277
|
March 30, 2023
|
HCSEC-2023-10 - Vault Vulnerable to Cache-Timing Attacks During Seal and Unseal Operations
|
|
0
|
7749
|
March 30, 2023
|
HCSEC-2023-07 - Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
|
|
0
|
6694
|
March 10, 2023
|
HCSEC-2023-02 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Go’s net/http (CVE-2022-41717)
|
|
0
|
5312
|
February 8, 2023
|
HCSEC-2022-24 - Vault's TLS Cert Auth Method Only Loaded CRL After First Request
|
|
0
|
6851
|
October 12, 2022
|
HCSEC-2022-18 - Vault Entity Alias Metadata May Leak Between Aliases With The Same Name Assigned To The Same Entity
|
|
0
|
7753
|
September 20, 2022
|
HCSEC-2022-15 - Vault Enterprise Does Not Verify Existing Voter Status When Joining An Integrated Storage HA Node
|
|
0
|
8277
|
July 26, 2022
|