Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxc5-78f8-rhp4

Опубликовано: 30 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.

This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.

This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
nvd
почти 2 года назад

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532