Sploitus

CVE-2024-2877

No indexed exploits for CVE-2024-2877 yet

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.

Affected products
Vault Enterprise
Hashicorp Vault
< 1.15.8
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-532
NVD status
Analyzed
Published
2024-04-30
Attack patterns
CAPEC-215
CVE-2024-2877 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-2877 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-2877 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.