Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw
option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw
.
{ "cpes": [ "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*", "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*" ], "severity": "Medium" }