Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8365

Опубликовано: 02 сент. 2024
Источник: redhat
CVSS3: 6.2

Описание

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

Отчет

This CVE affects Vault Community Edition and Vault Enterprise from 1.16.7 up to 1.17.3. The affected versions of Vault package are not shipped in any of the Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/ocs-must-gather-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-cli-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/ocs-metrics-exporter-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/ocs-must-gather-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=2308970vault: Vault Leaks Client Token and Token Accessor in Audit Devices

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
10 месяцев назад

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

CVSS3: 6.5
redos
9 месяцев назад

Уязвимость vault

CVSS3: 6.5
github
10 месяцев назад

Vault Leaks Client Token and Token Accessor in Audit Devices

CVSS3: 6.5
fstec
10 месяцев назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с вставкой конфиденциальной информации в файл журнала, позволяющая нарушителю получить доступ к конфиденциальной информации

6.2 Medium

CVSS3