HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
References
Link | Resource |
---|---|
https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#100-december-3rd-2018 | Release Notes Third Party Advisory |
Configurations
Information
Published : 2018-12-05 01:29
Updated : 2018-12-27 11:36
NVD link : CVE-2018-19786
Mitre link : CVE-2018-19786
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
hashicorp
- vault