Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-4525

4 месяца назад

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-4525

4 месяца назад

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-72gw-fmmr-c4r4

4 месяца назад

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-05665

4 месяца назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260529-73-0013

2 месяца назад

Уязвимость vault

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-4525

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4525

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-72gw-fmmr-c4r4

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-05665

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
0%
Низкий
4 месяца назад
redos логотип
ROS-20260529-73-0013

Уязвимость vault

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.