Vulnerabilities
Vulnerable Software
Hashicorp:  >> Vault  >> 1.15.12  Security Vulnerabilities
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.
CVSS Score
6.2
EPSS Score
0.003
Published
2024-09-02
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
CVSS Score
6.4
EPSS Score
0.007
Published
2024-04-04


Contact Us

Shodan ® - All rights reserved