Vulnerability Reporthashicorp/vault:1.2.7

hashicorp/vault:1.2.7
digestsha256:513b6a9e000034dccb8065a4b64597facfb2fe0499244a6e08e306c398ef7102

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. Although it contains 3 exposed and 14 post-exploit-only findings, all are low severity (maximum 4.67 and 3.51 respectively), and no high-severity issues were identified. The image is from a verified publisher and pinned by digest, reducing supply-chain risk. No known vulnerabilities meet the threshold to require additional attention.

Vulnerabilities

Vulnerability Log

18 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2020-28928MEDIUM4.67
musl
1.1.22-r3
fixed in 1.1.22-r4
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-23839LOW3.7
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23839LOW3.7
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23840LOW3.51
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Post-Exploit
CVE-2021-23840LOW3.51
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Post-Exploit
CVE-2021-36159LOW3.28
apk-tools
2.10.4-r2
fixed in 2.10.7-r0
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-3450LOW3.07
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Post-Exploit
CVE-2021-3450LOW3.07
libssl1.1
1.1.1g-r0
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Post-Exploit
CVE-2021-3449LOW2.76
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1k-r0
62.9%
Actively Exploited
Post-Exploit
CVE-2021-3449LOW2.76
libssl1.1
1.1.1g-r0
fixed in 1.1.1k-r0
62.9%
Actively Exploited
Post-Exploit
CVE-2021-30139LOW2.7
apk-tools
2.10.4-r2
fixed in 2.10.6-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-28831LOW2.7
busybox
1.30.1-r3
fixed in 1.30.1-r5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-28831LOW2.7
ssl_client
1.30.1-r3
fixed in 1.30.1-r5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2020-1971LOW2.12
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Post-Exploit
CVE-2021-23841LOW2.12
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Post-Exploit
CVE-2020-1971LOW2.12
libssl1.1
1.1.1g-r0
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Post-Exploit
CVE-2021-23841LOW2.12
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Post-Exploit
CVE-2020-28928NONE0
musl-utils
1.1.22-r3
fixed in 1.1.22-r4
0.6%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.