First published: Wed Dec 05 2018(Updated: )
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | <1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2018-19786.
The severity of vulnerability CVE-2018-19786 is high, with a severity value of 8.1.
HashiCorp Vault versions prior to 1.0.0 are affected by vulnerability CVE-2018-19786.
Vulnerability CVE-2018-19786 exposes the master key to the server log in certain unusual or misconfigured scenarios.
To fix vulnerability CVE-2018-19786, upgrade to a version of HashiCorp Vault that is equal to or newer than 1.0.0.