Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. HashiCorp/
  3. HashiCorp Vault

HashiCorp Vault

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 100 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Identity-based secrets mgmt platform for credentials, certs, keys & encryption

by HashiCorp · hashicorp.com · source ↗

Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2022-3920 ↗MEDIUM 5.32022

    HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

  • CVE-2022-3867 ↗LOW 2.72022

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

  • CVE-2022-3866 ↗MEDIUM 5.02022

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

  • CVE-2022-36182 ↗MEDIUM 6.12022

    Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions o…

  • CVE-2022-41316 ↗MEDIUM 5.32022

    HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list…

  • CVE-2022-41606 ↗MEDIUM 6.52022

    HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1…

  • CVE-2022-42717 ↗HIGH 7.82022

    An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-p…

  • CVE-2022-40716 ↗MEDIUM 6.52022

    HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass…

  • CVE-2021-41803 ↗HIGH 7.12022

    HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1…

  • CVE-2022-40186 ↗CRITICAL 9.12022

    An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with…

  • CVE-2022-36130 ↗CRITICAL 9.92022

    HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized u…

  • CVE-2022-38149 ↗HIGH 7.52022

    HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault se…

  • CVE-2022-36888 ↗MEDIUM 6.52022

    A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified…

  • CVE-2022-36129 ↗CRITICAL 9.12022

    HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node …

  • CVE-2022-30324 ↗CRITICAL 9.82022

    HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client ag…

  • CVE-2022-30689 ↗MEDIUM 5.32022

    HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault …

  • CVE-2022-29810 ↗MEDIUM 5.52022

    The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

  • CVE-2022-29153 ↗HIGH 7.52022

    HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fi…

  • CVE-2022-24685 ↗HIGH 7.52022

    HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.

  • CVE-2022-25374 ↗HIGH 7.52022

    HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.

  • …and 80 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Non-Human Identity & Secrets products

see all →
  • AI Agent Guardrails · Clutch Security
  • ANGOKA Machine Identity Management · ANGOKA
  • Access Control Plane · Aembit
  • Aembit IAM to Secure AI Agents & Workloads · Aembit
  • Agen for Workforce · Frontegg
  • Agentic Governance · NewCore
  • Akeyless AI Agent Security · Akeyless Security
  • Akeyless Secrets Management · Akeyless Security