Skip to content
VaultGHSA-jjxf-26c9-77gm

Vault Leaks Client Token and Token Accessor in Audit Devices

Medium6.5CVE-2024-8365 · Published Sep 2, 2024 · updated Sep 10, 2026

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.17.3, < 1.17.51.17.5
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
BIT-vault-2024-8365, CVE-2024-8365, GO-2024-3113

More Vault advisories

All Vault
Advisory
Hashicorp Vault vulnerable to denial of service through memory exhaustion
High7.5Oct 31, 2024
Vault Community Edition privilege escalation vulnerability
High7.2Oct 10, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
High7.5Jul 11, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
Low2.6Jun 12, 2024
HashiCorpVault does not correctly validate OCSP responses
Medium6.4Apr 4, 2024
Incorrect TLS certificate auth method in Vault
High8.1Mar 4, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.