CVE-2020-13223: Infoleak
HashiCorp Vault and Vault Enterprise before 1.3.6, and 1.4.2 before 1.4.2, insert Sensitive Information into a Log File. The vulnerability is affecting github.com/hashicorp/vault/command Go package.
Other sources
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this HashiCorp Vault vulnerability?
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2020-13223.
What is the severity of CVE-2020-13223?
The severity of CVE-2020-13223 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-13223?
HashiCorp Vault and Vault Enterprise versions before 1.3.6 and before 1.4.2 are affected by CVE-2020-13223.
How does CVE-2020-13223 impact HashiCorp Vault?
CVE-2020-13223 allows sensitive information to be inserted into a log file in HashiCorp Vault.
How can I fix CVE-2020-13223?
To fix CVE-2020-13223, upgrade HashiCorp Vault and Vault Enterprise to version 1.3.6 or 1.4.2.