Description

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

INFO

Published Date :

2024-09-02T01:30:56.618Z

Last Modified :

2024-09-04T17:18:36.980Z

Source :

HashiCorp
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8365 vulnerability.

Vendors Products
Hashicorp
  • Vault

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact