VDB
Sign up
MEDIUM6.5

GHSA-jjxf-26c9-77gm

Vault Leaks Client Token and Token Accessor in Audit Devices

Quick fix

GHSA-jjxf-26c9-77gm — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.17.5

Details

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 1.17.3Fixed in: 1.17.5
Fixgo get github.com/hashicorp/vault@v1.17.5

References