CVE-2024-0831 - CVE House
Back to Database
Status published Medium CVE-2024-0831

Vault May Expose Sensitive Information When Configuring An Audit Log Device

Vulnerability Description

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0831

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Vault, Vault Enterprise
Vulnerable Versions:
1.15.0

Timeline

Official Publish: February 1st, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)