Логотип exploitDog
bind:CVE-2025-4166
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4166

Количество 4

Количество 4

redhat логотип

CVE-2025-4166

около 2 месяцев назад

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2025-4166

около 2 месяцев назад

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

CVSS3: 4.5
EPSS: Низкий
redos логотип

ROS-20250616-10

4 дня назад

Уязвимость vault

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-gcqf-f89c-68hv

около 2 месяцев назад

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

CVSS3: 4.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-4166

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

CVSS3: 4.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-4166

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

CVSS3: 4.5
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20250616-10

Уязвимость vault

CVSS3: 4.5
0%
Низкий
4 дня назад
github логотип
GHSA-gcqf-f89c-68hv

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

CVSS3: 4.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу