Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2024-08718

около 3 лет назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с неправильной проверкой входных данных, позволяющая нарушителю задавать произвольные случайные значения (нонсы) при отключённой конвергентной криптографии

CVSS3: 6.8
EPSS: Низкий
redos логотип

ROS-20241015-07

почти 2 года назад

Уязвимость vault

CVSS3: 6.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-3678

больше 2 лет назад

ALT-PU-2024-3678: package `vault` update to version 1.13.12-alt2

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2024-3459

больше 2 лет назад

ALT-PU-2024-3459: package `vault` update to version 1.13.12-alt1

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-4680

почти 3 года назад

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2023-4680

около 3 лет назад

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-v84f-6r39-cpfc

около 3 лет назад

HashiCorp Vault Improper Input Validation vulnerability

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-08718

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с неправильной проверкой входных данных, позволяющая нарушителю задавать произвольные случайные значения (нонсы) при отключённой конвергентной криптографии

CVSS3: 6.8
0%
Низкий
около 3 лет назад
redos логотип
ROS-20241015-07

Уязвимость vault

CVSS3: 6.8
0%
Низкий
почти 2 года назад
altlinux логотип
ALT-PU-2024-3678

ALT-PU-2024-3678: package `vault` update to version 1.13.12-alt2

CVSS3: 7.5
больше 2 лет назад
altlinux логотип
ALT-PU-2024-3459

ALT-PU-2024-3459: package `vault` update to version 1.13.12-alt1

CVSS3: 7.5
больше 2 лет назад
redhat логотип
CVE-2023-4680

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4680

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-v84f-6r39-cpfc

HashiCorp Vault Improper Input Validation vulnerability

CVSS3: 6.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу