Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0732 Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.
Github GHSA Github GHSA GHSA-vgh3-mwxq-rcp8 Hashicorp Vault may expose sensitive log information
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2025-02-13T17:27:29.010Z

Reserved: 2024-01-23T17:42:40.228Z

Link: CVE-2024-0831

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.883Z

cve-icon NVD

Status : Modified

Published: 2024-02-01T02:15:46.330

Modified: 2024-11-21T08:47:28.063

Link: CVE-2024-0831

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-01T00:00:00Z

Links: CVE-2024-0831 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses