Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate severity
GitHub Reviewed
Published
May 2, 2025
to the GitHub Advisory Database
•
Updated May 6, 2025
Package
Affected versions
>= 0.3.0, < 1.19.3
Patched versions
1.19.3
Description
Published by the National Vulnerability Database
May 2, 2025
Published to the GitHub Advisory Database
May 2, 2025
Reviewed
May 2, 2025
Last updated
May 6, 2025
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
References