2024-12-08 03:06:42 +00:00

72 lines
2.7 KiB
JSON

{
"id": "CVE-2024-2877",
"sourceIdentifier": "security@hashicorp.com",
"published": "2024-04-30T15:15:52.740",
"lastModified": "2024-11-21T09:10:44.020",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.\n\nThis vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8."
},
{
"lang": "es",
"value": "Vault Enterprise, cuando se configura con nodos en espera de rendimiento y un dispositivo de auditor\u00eda configurado, registrar\u00e1 inadvertidamente encabezados de solicitud en el nodo en espera. Es posible que estos registros hayan incluido informaci\u00f3n confidencial de solicitudes HTTP en texto plano. Esta vulnerabilidad, CVE-2024-2877, se solucion\u00f3 en Vault Enterprise 1.15.8."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@hashicorp.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.1,
"impactScore": 4.0
}
]
},
"weaknesses": [
{
"source": "security@hashicorp.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"references": [
{
"url": "https://discuss.hashicorp.com/t/hsec-2024-10-vault-enterprise-leaks-sensitive-http-request-headers-in-audit-log-when-deployed-with-a-performance-standby-node",
"source": "security@hashicorp.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240614-0002/",
"source": "security@hashicorp.com"
},
{
"url": "https://discuss.hashicorp.com/t/hsec-2024-10-vault-enterprise-leaks-sensitive-http-request-headers-in-audit-log-when-deployed-with-a-performance-standby-node",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240614-0002/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}