Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjxf-26c9-77gm

Опубликовано: 02 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6
CVSS3: 6.5

Описание

Vault Leaks Client Token and Token Accessor in Audit Devices

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.17.3, < 1.17.5

1.17.5

EPSS

Процентиль: 23%
0.00073
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.2
redhat
10 месяцев назад

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

CVSS3: 6.2
nvd
10 месяцев назад

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

CVSS3: 6.5
redos
9 месяцев назад

Уязвимость vault

CVSS3: 6.5
fstec
10 месяцев назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с вставкой конфиденциальной информации в файл журнала, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 23%
0.00073
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-532