Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.
History

Wed, 04 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp vault
CPEs cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
Vendors & Products Hashicorp
Hashicorp vault

Tue, 03 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 02 Sep 2024 02:15:00 +0000

Type Values Removed Values Added
Description Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.
Title Vault Leaks AppRole Client Tokens And Accessor in Audit Log
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published: 2024-09-02T01:30:56.618Z

Updated: 2024-09-04T17:18:36.980Z

Reserved: 2024-08-30T22:54:58.745Z

Link: CVE-2024-8365

cve-icon Vulnrichment

Updated: 2024-09-03T13:51:45.751Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-02T05:15:17.823

Modified: 2024-09-04T14:37:03.543

Link: CVE-2024-8365

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-02T05:15:17Z

Links: CVE-2024-8365 - Bugzilla