VaultGHSA-jjxf-26c9-77gm
Vault Leaks Client Token and Token Accessor in Audit Devices
Medium6.5CVE-2024-8365 · Published Sep 2, 2024 · updated Sep 10, 2026
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.17.3, < 1.17.5 | 1.17.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-vault-2024-8365, CVE-2024-8365, GO-2024-3113
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | Hashicorp Vault vulnerable to denial of service through memory exhaustion | High7.5 | 1.18.1+1 more |
| Oct 102024 | Vault Community Edition privilege escalation vulnerability | High7.2 | 1.18.0+1 more |
| Jul 112024 | Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions | High7.5 | 1.15.12+2 more |
| Jun 122024 | HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims | Low2.6 | 1.15.9+2 more |
| Apr 42024 | HashiCorpVault does not correctly validate OCSP responses | Medium6.4 | 1.16.0 |
| Mar 42024 | Incorrect TLS certificate auth method in Vault | High8.1 | 1.14.10+1 more |