Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8365

Опубликовано: 02 сент. 2024
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

Отчет

This CVE affects Vault Community Edition and Vault Enterprise from 1.16.7 up to 1.17.3. The affected versions of Vault package are not shipped in any of the Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/ocs-must-gather-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-cli-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/ocs-metrics-exporter-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/ocs-must-gather-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=2308970vault: Vault Leaks Client Token and Token Accessor in Audit Devices

EPSS

Процентиль: 14%
0.00048
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
около 1 года назад

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

CVSS3: 6.5
redos
12 месяцев назад

Уязвимость vault

CVSS3: 6.5
github
около 1 года назад

Vault Leaks Client Token and Token Accessor in Audit Devices

CVSS3: 6.5
fstec
около 1 года назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с вставкой конфиденциальной информации в файл журнала, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 14%
0.00048
Низкий

6.2 Medium

CVSS3