<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hashicorp Vault</title>
  <link>https://cvedaily.com/pages/tags/hashicorp-vault.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hashicorp-vault.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hashicorp Vault</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:55 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-39946 – OpenBao is an open source identity-based secrets management system. Prior to ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39946</guid>
    <pubDate>Tue, 21 Apr 2026 01:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39946</strong></p>
  <p>OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-39388 – OpenBao is an open source identity-based secrets management system. Prior to ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39388</guid>
    <pubDate>Tue, 21 Apr 2026 01:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-39388</strong></p>
  <p>OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matches the original. Token renewals for other authentication methods do not require any supplied login information. Due to i…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68476 – KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68476</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68476</strong></p>
  <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token spe…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67642 – Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67642</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67642</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-45744 – TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45744</guid>
    <pubDate>Fri, 27 Sep 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-45744</strong></p>
  <p>TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiC…</p>
  <p><strong>CVSS:</strong> 3.0 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-43808 – In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43808</guid>
    <pubDate>Fri, 16 Aug 2024 15:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-43808</strong></p>
  <p>In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6337 – HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6337</guid>
    <pubDate>Fri, 08 Dec 2023 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6337</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.  Fixed in Vault 1.15.4, 1.14.8, 1.13.12.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5954 – HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5954</guid>
    <pubDate>Thu, 09 Nov 2023 21:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5954</strong></p>
  <p>HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4680 – HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4680</guid>
    <pubDate>Fri, 15 Sep 2023 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4680</strong></p>
  <p>HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 an…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-323</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33001 – Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33001</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33001</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-2197 – HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2197</guid>
    <pubDate>Mon, 01 May 2023 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-2197</strong></p>
  <p>HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25000 – HashiCorp Vault's implementation of Shamir's secret sharing used precomputed tab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25000</guid>
    <pubDate>Thu, 30 Mar 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25000</strong></p>
  <p>HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0665 – HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0665</guid>
    <pubDate>Thu, 30 Mar 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0665</strong></p>
  <p>HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0620 – HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0620</guid>
    <pubDate>Thu, 30 Mar 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0620</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command.  This…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24999 – HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24999</guid>
    <pubDate>Sat, 11 Mar 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24999</strong></p>
  <p>HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41316 – HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41316</guid>
    <pubDate>Wed, 12 Oct 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41316</strong></p>
  <p>HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40186 – An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40186</guid>
    <pubDate>Thu, 22 Sep 2022 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40186</strong></p>
  <p>An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths usin…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36888 – A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36888</guid>
    <pubDate>Wed, 27 Jul 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36888</strong></p>
  <p>A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36129 – HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters usin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36129</guid>
    <pubDate>Tue, 26 Jul 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36129</strong></p>
  <p>HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-30689 – HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30689</guid>
    <pubDate>Tue, 17 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-30689</strong></p>
  <p>HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25197 – Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25197</guid>
    <pubDate>Tue, 15 Feb 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25197</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25186 – Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25186</guid>
    <pubDate>Tue, 15 Feb 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25186</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23109 – Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23109</guid>
    <pubDate>Wed, 12 Jan 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23109</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-45042 – In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45042</guid>
    <pubDate>Fri, 17 Dec 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-45042</strong></p>
  <p>In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43837 – vault-cli is a configurable command-line interface tool (and python library) to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43837</guid>
    <pubDate>Thu, 16 Dec 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43837</strong></p>
  <p>vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safel…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-43998 – HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43998</guid>
    <pubDate>Tue, 30 Nov 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-43998</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-42135 – HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42135</guid>
    <pubDate>Mon, 11 Oct 2021 03:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-42135</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-41802 – HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41802</guid>
    <pubDate>Fri, 08 Oct 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-41802</strong></p>
  <p>HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27668 – HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27668</guid>
    <pubDate>Tue, 31 Aug 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27668</strong></p>
  <p>HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38554 – HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38554</guid>
    <pubDate>Fri, 13 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38554</strong></p>
  <p>HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38553 – HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlyi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38553</guid>
    <pubDate>Fri, 13 Aug 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38553</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32923 – HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32923</guid>
    <pubDate>Thu, 03 Jun 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32923</strong></p>
  <p>HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32074 – HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32074</guid>
    <pubDate>Fri, 07 May 2021 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32074</strong></p>
  <p>HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29653 – HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstance...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29653</guid>
    <pubDate>Thu, 22 Apr 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29653</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27400 – HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27400</guid>
    <pubDate>Thu, 22 Apr 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27400</strong></p>
  <p>HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3282 – HashiCorp Vault Enterprise 1.6.0 &amp; 1.6.1 allowed the `remove-peer` raft operator...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3282</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3282</strong></p>
  <p>HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3024 – HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3024</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3024</strong></p>
  <p>HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25594 – HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25594</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25594</strong></p>
  <p>HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-35453 – HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35453</guid>
    <pubDate>Thu, 17 Dec 2020 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-35453</strong></p>
  <p>HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-35177 – HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35177</guid>
    <pubDate>Thu, 17 Dec 2020 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-35177</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25816 – HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases creat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25816</guid>
    <pubDate>Wed, 30 Sep 2020 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25816</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16251 – HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16251</guid>
    <pubDate>Wed, 26 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16251</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16250 – HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16250</guid>
    <pubDate>Wed, 26 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16250</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24359 – HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24359</guid>
    <pubDate>Thu, 20 Aug 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24359</strong></p>
  <p>HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13223 – HashiCorp Vault and Vault Enterprise logged proxy environment variables that pot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13223</guid>
    <pubDate>Wed, 10 Jun 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13223</strong></p>
  <p>HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12757 – HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12757</guid>
    <pubDate>Wed, 10 Jun 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12757</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10661 – HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under ce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10661</guid>
    <pubDate>Mon, 23 Mar 2020 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10661</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10660 – HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10660</guid>
    <pubDate>Mon, 23 Mar 2020 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10660</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7220 – HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7220</guid>
    <pubDate>Thu, 23 Jan 2020 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7220</strong></p>
  <p>HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19786 – HashiCorp Vault before 1.0.0 writes the master key to the server log in certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19786</guid>
    <pubDate>Wed, 05 Dec 2018 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19786</strong></p>
  <p>HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19786">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
