MEDIUM 4.5 Go

Hashicorp Vault may expose sensitive log information

GHSA-vgh3-mwxq-rcp8 · BIT-vault-2024-0831 · CVE-2024-0831 · GO-2024-2511

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw

Ready to move

Start Securing

Free, no credit card | First findings in minutes