HashiCorp Vagrant 1.2.6

CPE Details

HashiCorp Vagrant 1.2.6
1.2.6
2022-10-18
14h56 +00:00
2022-10-19
01h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hashicorp:vagrant:1.2.6:*:*:*:*:*:*:*

Informations

Vendor

hashicorp

Product

vagrant

Version

1.2.6

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-5834 2023-10-27 21h06 +00:00 HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
7.8
High
CVE-2022-42717 2022-10-10 22h00 +00:00 An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.
7.8
High