Medium severity5.5NVD Advisory· Published Apr 30, 2024· Updated Jun 17, 2026
CVE-2024-2877
CVE-2024-2877
Description
Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext.
This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.
Affected products
41.15.0+ 1 more
- (no CPE)range: 1.15.0
- (no CPE)range: before 1.15.8
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.