Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgh3-mwxq-rcp8

Опубликовано: 01 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.5

Описание

Hashicorp Vault may expose sensitive log information

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.5

1.15.5

EPSS

Процентиль: 37%
0.00156
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.5
redhat
около 2 лет назад

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.

CVSS3: 4.5
nvd
около 2 лет назад

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.

EPSS

Процентиль: 37%
0.00156
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-532