HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
References
Link | Resource |
---|---|
https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#100-december-3rd-2018 | Release Notes Third Party Advisory |
https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#100-december-3rd-2018 | Release Notes Third Party Advisory |
Configurations
History
21 Nov 2024, 03:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#100-december-3rd-2018 - Release Notes, Third Party Advisory |
Information
Published : 2018-12-05 09:29
Updated : 2024-11-21 03:58
NVD link : CVE-2018-19786
Mitre link : CVE-2018-19786
CVE.ORG link : CVE-2018-19786
JSON object : View
Products Affected
hashicorp
- vault
CWE
CWE-532
Insertion of Sensitive Information into Log File