HCSEC-2022-12 - Vault’s Login MFA Configuration And Enforcement Not Reloaded After Restart
|
|
0
|
4240
|
May 16, 2022
|
HCSEC-2022-09 - Vault PKI Secrets Engine Policy Results In Incorrect Wildcard Certificate Issuance
|
|
0
|
7942
|
March 4, 2022
|
HCSEC-2022-08 - Vault Enterprise’s Tokenization Transform Configuration Endpoint May Expose Transform Key
|
|
0
|
7214
|
March 4, 2022
|
HCSEC-2021-30 - Vault's Templated ACL Policies Matched First-Created Alias Per Entity and Auth Backend
|
|
1
|
8165
|
January 6, 2022
|
HCSEC-2021-34 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Golang’s net/http (CVE-2021-44716)
|
|
0
|
5101
|
December 22, 2021
|
HCSEC-2021-33 - Vault’s KV Secrets Engine With Integrated Storage Exposed to Authenticated Denial of Service
|
|
0
|
7076
|
December 14, 2021
|
HCSEC-2021-28 - Vault's Google Cloud Secrets Engine Policies With Globs May Provide Additional Privileges in Vault 1.8.0 Onwards
|
|
0
|
7313
|
October 7, 2021
|
HCSEC-2021-27 - Vault Merging Multiple Entity Aliases for the Same Mount May Allow Privilege Escalation
|
|
0
|
8279
|
October 7, 2021
|
HCSEC-2020-20 - Vault Leases Created with Batch Tokens have Invalid Expiration
|
|
1
|
4499
|
September 2, 2021
|
HCSEC-2021-20 - Vault’s Integrated Storage Backend Database File May Have Excessively Broad Permissions
|
|
1
|
9022
|
September 2, 2021
|
HCSEC-2021-19 - Vault’s UI Cached User-Viewed Secrets Between Shared Browser Sessions
|
|
0
|
7749
|
August 12, 2021
|
HCSEC-2021-15 - Vault Renewed Nearly-Expired Leases With Incorrect Non-Expiring TTLs
|
|
1
|
8388
|
June 2, 2021
|
HCSEC-2021-13 - Vault GitHub Action Did Not Correctly Mask Multi-Line Secrets In Output
|
|
0
|
7616
|
May 6, 2021
|
HCSEC-2021-12 - Codecov Security Event and HashiCorp GPG Key Exposure
|
|
2
|
66759
|
May 4, 2021
|
HCSEC-2021-10 - Vault’s Cassandra Integrations Did Not Validate TLS Certificates
|
|
0
|
7510
|
April 21, 2021
|
HCSEC-2021-11 - Terraform’s Vault Provider Did Not Correctly Configure Bound Labels for GCP Auth
|
|
0
|
8140
|
April 21, 2021
|
HCSEC-2021-09 - Vault’s PKI Engine CRL May Exclude Revoked But Unexpired Certificates After Tidy
|
|
0
|
8536
|
April 21, 2021
|
HCSEC-2021-05 - Vault Enterprise’s DR Secondaries Exposed License Metadata Without Authentication
|
|
0
|
7456
|
February 26, 2021
|
HCSEC-2021-03 - Vault API Endpoint Allowed Enumeration of Secrets Engine Mount Paths Without Authentication
|
|
0
|
8313
|
January 29, 2021
|
HCSEC-2021-02 - Vault API Endpoint Exposed Internal IP Address Without Authentication
|
|
0
|
8008
|
January 29, 2021
|
HCSEC-2021-04 - Vault Enterprise’s DR Secondaries Allowed Raft Peer Removal Without Authentication
|
|
0
|
7751
|
January 29, 2021
|
HCSEC-2020-25 - Vault’s LDAP Auth Method Allows User Enumeration
|
|
0
|
7970
|
December 16, 2020
|
HCSEC-2020-24 - Vault Enterprise’s Sentinel EGP Policies May Impact Parent or Sibling Namespaces
|
|
0
|
7302
|
December 16, 2020
|
HCSEC-2020-18 - Vault SSH Helper Validated IP Addresses Incorrectly
|
|
0
|
4128
|
November 25, 2020
|
HCSEC-2020-17 - Vault’s GCP Auth Method Allows Authentication Bypass
|
|
0
|
4201
|
November 25, 2020
|
HCSEC-2020-16 - Vault’s AWS Auth Method Allows Authentication Bypass
|
|
0
|
4396
|
November 25, 2020
|
HCSEC-2020-13 - Vault Proxy Environment Variable Was Logged to STDOUT
|
|
0
|
4152
|
November 25, 2020
|
HCSEC-2020-09 - Vault's GCP Secrets Engine Service Account Keys Not Enforcing Configured TTL
|
|
0
|
4121
|
November 25, 2020
|
HCSEC-2020-07 - Vault Enterprise Prefixed Mount Policies May Result In Unauthorized Namespace Access
|
|
0
|
4139
|
November 25, 2020
|
HCSEC-2020-06 - Vault Auth Groups Not Removed In Certain Circumstances
|
|
0
|
4075
|
November 25, 2020
|