Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hashicorp
Hashicorp vault |
|
CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
|
Vendors & Products |
Hashicorp
Hashicorp vault |
Tue, 03 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Sep 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 02 Sep 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9. | |
Title | Vault Leaks AppRole Client Tokens And Accessor in Audit Log | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: HashiCorp
Published: 2024-09-02T01:30:56.618Z
Updated: 2024-09-04T17:18:36.980Z
Reserved: 2024-08-30T22:54:58.745Z
Link: CVE-2024-8365
Vulnrichment
Updated: 2024-09-03T13:51:45.751Z
NVD
Status : Analyzed
Published: 2024-09-02T05:15:17.823
Modified: 2024-09-04T14:37:03.543
Link: CVE-2024-8365
Redhat