Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4166

Опубликовано: 02 мая 2025
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

Меры по смягчению последствий

Customers with the capability to search through server and audit logs for any possible exposed secrets can refer to the following snippets to aid in searching. More information on viewing audit and server logs can be found at: https://developer.hashicorp.com/vault/tutorials/monitoring/troubleshooting-vault#vault-logs

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Fix deferred
Red Hat Openshift Data Foundation 4odf4/mcg-cli-rhel9Fix deferred
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorFix deferred
Red Hat Openshift Data Foundation 4odf4/odf-cli-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2363669vault: Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin

EPSS

Процентиль: 8%
0.00033
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
nvd
около 2 месяцев назад

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

CVSS3: 4.5
redos
3 дня назад

Уязвимость vault

CVSS3: 4.5
github
около 2 месяцев назад

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

EPSS

Процентиль: 8%
0.00033
Низкий

4.5 Medium

CVSS3