Back

MEDIUM

Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin

Published May 2, 2025

Description

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

Affected products

Remediation

Red Hat mitigation

Customers with the capability to search through server and audit logs for any possible exposed secrets can refer to the following snippets to aid in searching. More information on viewing audit and server logs can be found at: https://developer.hashicorp.com/vault/tutorials/monitoring/troubleshooting-vault#vault-logs

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HashiCorp
Published May 2, 2025
Updated May 8, 2025
Reserved Apr 30, 2025
CISA Vulnrichment
Updated May 2, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 2, 2025
GHSA-GCQF-F89C-68HV