Intel

AIKIDO-2024-10240

github.com/hashicorp/vault is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log FileCVE-2024-8365 Published Sep 3, 2024

61

Medium Risk

This Affects:

gogithub.com/hashicorp/vault
1.17.3 - 1.17.4
Fixed in 1.17.5
Are you affected? Scan for Free

TL;DR

Affected versions of the package insert sensitive information into log files. Every interaction, including requests containing Vault tokens, client tokens, or other sensitive data, is logged to the audit device. A regression in these versions removed the hashing functionality, resulting in the plaintext values being stored in the audit logs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/vault is vulnerable to Insertion of Sensitive Information into Log File in versions 1.17.3 - 1.17.4.

How to fix this

Upgrade the github.com/hashicorp/vault library to the patch version.