CVE-2020-13223Log File Information Exposure in Hashicorp Vault

Severity
7.5HIGHNVD
EPSS
0.4%
top 40.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateAug 21

Description

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDhashicorp/vault1.4.01.4.2+1
Gogithub.com/hashicorp_vault1.3.01.3.6+1

🔴Vulnerability Details

3
OSV
Information Disclosure in HashiCorp Vault in github.com/hashicorp/vault2024-08-21
OSV
Information Disclosure in HashiCorp Vault2021-05-18
GHSA
Information Disclosure in HashiCorp Vault2021-05-18

📋Vendor Advisories

1
Red Hat
vault: Information disclosure from logged proxy environment variables2020-05-21