github.com/hashicorp/vault is vulnerable to Insertion of Sensitive Information into Log File
61
Medium Risk
Affected versions of the package insert sensitive information into log files. Every interaction, including requests containing Vault tokens, client tokens, or other sensitive data, is logged to the audit device. A regression in these versions removed the hashing functionality, resulting in the plaintext values being stored in the audit logs.
You are affected if you are using a version that falls within the vulnerable range.
github.com/hashicorp/vault is vulnerable to Insertion of Sensitive Information into Log File in versions 1.17.3 - 1.17.4.
Upgrade the github.com/hashicorp/vault library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant