PT-2024-22569 · Hashicorp · Vault Enterprise

CVE-2024-2877

·

Published

2024-04-30

·

Updated

2025-08-08

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vault Enterprise versions prior to 1.15.8
Description The issue arises when Vault Enterprise is configured with performance standby nodes and a configured audit device, causing it to inadvertently log request headers on the standby node. These logs may include sensitive HTTP request information in cleartext.
Recommendations For versions prior to 1.15.8, update to Vault Enterprise 1.15.8 to resolve the issue. As a temporary workaround, consider restricting access to the audit device on performance standby nodes until the update is applied.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-VAULT-2024-2877
CVE-2024-2877

Affected Products

Vault Enterprise