CVE-2024-0831

Source
https://cve.org/CVERecord?id=CVE-2024-0831
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0831.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0831
Aliases
Published
2024-02-01T01:41:33.801Z
Modified
2026-07-15T01:49:07.832090603Z
Severity
  • 4.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Vault May Expose Sensitive Information When Configuring An Audit Log Device
Details

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw.

Database specific
{
    "cwe_ids": [
        "CWE-532"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0831.json",
    "cna_assigner": "HashiCorp"
}
References

Affected packages

Git / github.com/hashicorp/vault

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/vault
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.15.0"
        },
        {
            "last_affected": "1.15.4"
        },
        {
            "fixed": "1.15.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

sdk/v0.*
sdk/v0.10.2
v1.*
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0831.json"