CVE-2024-0831

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 08:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.5
References () https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration - Exploit, Vendor Advisory () https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration - Exploit, Vendor Advisory
References () https://discuss.hashicorp.com/t/hcsec-2024-01-vault-may-expose-sensitive-information-when-configuring-an-audit-log-device/62311 - Vendor Advisory () https://discuss.hashicorp.com/t/hcsec-2024-01-vault-may-expose-sensitive-information-when-configuring-an-audit-log-device/62311 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240223-0005/ - () https://security.netapp.com/advisory/ntap-20240223-0005/ -

23 Feb 2024, 16:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240223-0005/ -

09 Feb 2024, 15:16

Type Values Removed Values Added
CPE cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Hashicorp
Hashicorp vault
CWE CWE-532
References () https://discuss.hashicorp.com/t/hcsec-2024-01-vault-may-expose-sensitive-information-when-configuring-an-audit-log-device/62311 - () https://discuss.hashicorp.com/t/hcsec-2024-01-vault-may-expose-sensitive-information-when-configuring-an-audit-log-device/62311 - Vendor Advisory
References () https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration - () https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration - Exploit, Vendor Advisory

01 Feb 2024, 16:17

Type Values Removed Values Added
References
  • {'url': 'https://link-to-discuss', 'name': 'https://link-to-discuss', 'tags': [], 'refsource': ''}
  • () https://discuss.hashicorp.com/t/hcsec-2024-01-vault-may-expose-sensitive-information-when-configuring-an-audit-log-device/62311 -

01 Feb 2024, 03:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-01 02:15

Updated : 2024-11-21 08:47


NVD link : CVE-2024-0831

Mitre link : CVE-2024-0831

CVE.ORG link : CVE-2024-0831


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-532

Insertion of Sensitive Information into Log File