CVE-2024-0831: Vault May Expose Sensitive Information When Configuring An Audit Log Device
Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the lograw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use lograw
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0831?
CVE-2024-0831 is classified as a medium severity vulnerability affecting Vault and Vault Enterprise.
How do I fix CVE-2024-0831?
To remediate CVE-2024-0831, upgrade to Vault version 1.15.5 or later.
What products are affected by CVE-2024-0831?
CVE-2024-0831 affects HashiCorp Vault and Vault Enterprise versions between 1.15.0 and 1.15.5.
What kind of information could be exposed by CVE-2024-0831?
CVE-2024-0831 may expose sensitive information that is logged when using the audit device with the log_raw option enabled.
Is there a way to mitigate CVE-2024-0831 without upgrading?
The best practice to mitigate CVE-2024-0831 is to avoid using the log_raw option in audit devices until an upgrade can be performed.