PT-2018-15092 · Hashicorp · Hashicorp Vault

Published

2018-12-05

·

Updated

2018-12-27

·

CVE-2018-19786

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.0.0
Description The issue arises in certain unusual or misconfigured scenarios where incorrect data comes from the autoseal mechanism without an error being reported, causing the master key to be written to the server log.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19786

Affected Products

Hashicorp Vault