HIGH 7.5 Go

Information Disclosure in HashiCorp Vault

GHSA-25xj-89g5-fm6h · BIT-vault-2020-13223 · CVE-2020-13223 · GO-2022-0778

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

HashiCorp Vault and Vault Enterprise before 1.3.6, and 1.4.2 before 1.4.2, insert Sensitive Information into a Log File. The vulnerability is affecting github.com/hashicorp/vault/command Go package.

Ready to move

Start Securing

Free, no credit card | First findings in minutes