CVE-2018-19786: High severity hashicorp vault vulnerability
Published Dec 5, 2018
·Updated
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
Affected Software
1 affected component
HashiCorp Vault<1.0.0
Event History
Dec 5, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this HashiCorp Vault vulnerability?
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2018-19786.
2
What is the severity of vulnerability CVE-2018-19786?
The severity of vulnerability CVE-2018-19786 is high, with a severity value of 8.1.
3
What is affected by vulnerability CVE-2018-19786?
HashiCorp Vault versions prior to 1.0.0 are affected by vulnerability CVE-2018-19786.
4
What is the impact of vulnerability CVE-2018-19786?
Vulnerability CVE-2018-19786 exposes the master key to the server log in certain unusual or misconfigured scenarios.
5
How can I fix vulnerability CVE-2018-19786?
To fix vulnerability CVE-2018-19786, upgrade to a version of HashiCorp Vault that is equal to or newer than 1.0.0.