Vulnerability Reporthashicorp/vault:1.3.10

hashicorp/vault:1.3.10
digestsha256:fa073f506d7d1a85175a8700e3d82ea9143ac57342b22b8e0ee2593f0804e89c

Executive Summary

Last scanned:

Threat Score
74/100NEEDS ATTENTION
Reputation
TRUSTED

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

18 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2021-23840CRITICAL9.75
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Directly Exposed
CVE-2021-23840CRITICAL9.75
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Directly Exposed
CVE-2021-3450HIGH8.51
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Directly Exposed
CVE-2021-3450HIGH8.51
libssl1.1
1.1.1g-r0
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Directly Exposed
CVE-2021-3449HIGH7.67
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1k-r0
62.9%
Actively Exploited
Directly Exposed
CVE-2021-3449HIGH7.67
libssl1.1
1.1.1g-r0
fixed in 1.1.1k-r0
62.9%
Actively Exploited
Directly Exposed
CVE-2020-1971MEDIUM5.9
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23841MEDIUM5.9
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-1971MEDIUM5.9
libssl1.1
1.1.1g-r0
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23841MEDIUM5.9
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Directly Exposed
CVE-2021-36159MEDIUM5.46
apk-tools
2.10.4-r2
fixed in 2.10.7-r0
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2020-28928MEDIUM4.67
musl
1.1.22-r3
fixed in 1.1.22-r4
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-30139MEDIUM4.5
apk-tools
2.10.4-r2
fixed in 2.10.6-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-28831MEDIUM4.5
busybox
1.30.1-r3
fixed in 1.30.1-r5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-28831MEDIUM4.5
ssl_client
1.30.1-r3
fixed in 1.30.1-r5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-23839LOW3.7
libcrypto1.1
1.1.1g-r0
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23839LOW3.7
libssl1.1
1.1.1g-r0
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-28928NONE0
musl-utils
1.1.22-r3
fixed in 1.1.22-r4
0.6%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.