CVE-2024-2877

CVSS V2 None CVSS V3 None
Description
Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.
Overview
  • CVE ID
  • CVE-2024-2877
  • Assigner
  • HashiCorp
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-30T14:58:09.735Z
  • Last Modified Date
  • 2024-06-21T15:56:24.200Z
History
Created Old Value New Value Data Type Notes
2024-06-26 00:18:04 Added to TrackCVE