Количество 5
Количество 5
CVE-2026-4525
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
CVE-2026-4525
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
GHSA-72gw-fmmr-c4r4
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
BDU:2026-05665
Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ROS-20260529-73-0013
Уязвимость vault
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-4525 If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-4525 If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-72gw-fmmr-c4r4 HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
BDU:2026-05665 Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260529-73-0013 Уязвимость vault | CVSS3: 7.5 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу