Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-2877

Опубликовано: 30 апр. 2024
Источник: nvd
CVSS3: 5.5
CVSS3: 5.5
EPSS Низкий

Описание

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.

This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
Версия от 1.15.0 (включая) до 1.15.8 (исключая)

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
github
почти 2 года назад

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

EPSS

Процентиль: 18%
0.00057
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-532