CVE Vulnerabilities

CVE-2024-2877

Insertion of Sensitive Information into Log File

Published: Apr 30, 2024 | Modified: Aug 08, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.

This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Vault Hashicorp 1.15.0 (including) 1.15.8 (excluding)

Potential Mitigations

References