Impact
The vulnerability manifests when failed API calls in the Node.js library rethrow an AxiosError that still contains the request configuration and response. These objects can include the Vault token in the X‑Vault‑Token header and secret/password data in the request body. When an application logs or otherwise exposes the error, the live credential can be written in plaintext to logs or monitoring services, allowing an attacker to retrieve a working Vault token. With that token, an attacker can access the Vault instance according to the token’s policy, potentially reading or modifying secrets, resources, or infrastructure state.
Affected Systems
The affected component is the hashi‑vault‑js library (kyndryl‑open‑source:hashi‑vault‑js). All releases earlier than 0.5.2 are vulnerable; the fix was introduced in version 0.5.2.
Risk and Exploitability
The CVSS score is 5.8, indicating moderate severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack requires an application that logs errors and an attacker who can read those logs or monitoring output. If such access is obtained, the exposed token provides direct authentication to the Vault, enabling further abuse of the environment.
OpenCVE Enrichment
Github GHSA