Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-32923: HashiCorp Blog: Vault

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVE
#web#microsoft#aws

October 24 2022 | Products & Technology

X.509 Certificate Management with Vault

In this blog post, we’ll look at practical public key certificate management in HashiCorp Vault using dynamic secrets rotation.

October 21 2022 | Company

HashiConf Global 2022: From Zero Trust to No Code

Check out the highlights from HashiConf Global 2022 and watch the 40+ keynote and session recordings now live on YouTube.

October 19 2022 | Company

New Competency Program Validates Systems Integrators’ HashiCorp Expertise

The new Technical Competency Program for Systems Integrators allows partners to display earned competency badges on both their own website and HashiCorp.com.

October 18 2022 | Products & Technology

Cockroach Labs, ForgeRock & Palo Alto Networks Highlight New Vault Integrations

The HashiCorp Vault ecosystem saw multiple integrations from partners Cockroach Labs, ForgeRock, and PaloAlto Networks as part of the 19 integrations completed this past quarter.

October 05 2022 | Products & Technology

HCP Vault on Microsoft Azure Now in Public Beta

In addition to its availability on AWS, HCP Vault can now be deployed on Microsoft Azure infrastructure.

September 15 2022 | Company

HashiCorp Tools Explained Using a Minecraft World

Visit our Minecraft world and learn how HashiCorp Vault, Consul, Nomad, and Boundary all work through fun analogies. Join us at HashiConf Global 2022 — in Los Angeles or online Oct. 4-6.

Related news

Gentoo Linux Security Advisory 202207-01

Gentoo Linux Security Advisory 202207-1 - Multiple vulnerabilities have been discovered in HashiCorp Vault, the worst of which could result in denial of service. Versions less than 1.10.3 are affected.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907