Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use log_raw
{
"nvd_published_at": "2024-02-01T02:15:46Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-532"
],
"github_reviewed_at": "2024-02-01T20:52:34Z"
}