Vulnerability CVE-2024-0831


Published: 2024-02-01

Description:
Vault and Vault Enterprise (??Vault?) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.

 References:
https://link-to-discuss
https://developer.hashicorp.com/vault/docs/upgrading/upgrade-to-1.15.x#audit-devices-could-log-raw-data-despite-configuration

Copyright 2026, cxsecurity.com

 

Back to Top