Database/Control plane, storage & DevOps
HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requests
CVSS 4.5CVE-2025-4166Control plane, storage & DevOpscurated
Impact
KV v2 leaks sensitive payload content into server and audit logs on malformed requests
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; scrub and re-secure the audit log store
References
Related entries
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfsCVE-2021-27363 · Linux iSCSIMedium
- IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before theirCVE-2021-38882 · IBM Spectrum Scale file audit logging retentionMedium
- Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkitCVE-2022-21894 · Windows Boot ManagerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.