{"id":"GHSA-25xj-89g5-fm6h","summary":"Information Disclosure in HashiCorp Vault","details":"HashiCorp Vault and Vault Enterprise before 1.3.6, and 1.4.2 before 1.4.2, insert Sensitive Information into a Log File. The vulnerability is affecting `github.com/hashicorp/vault/command` Go package.","aliases":["BIT-vault-2020-13223","CVE-2020-13223","GO-2022-0778"],"modified":"2024-08-21T15:57:13.896243Z","published":"2021-05-18T18:21:09Z","database_specific":{"nvd_published_at":"2020-06-10T19:15:00Z","cwe_ids":["CWE-200","CWE-532"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-13T14:30:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13223"},{"type":"WEB","url":"https://github.com/hashicorp/vault/commit/87f47c216cf1a28f4054b80cff40de8c9e00e36c"},{"type":"WEB","url":"https://github.com/hashicorp/vault/commit/e52f34772affb69f3239b2cdf6523cb7cfd67a92"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault"},{"type":"WEB","url":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#142-may-21st-2020"},{"type":"WEB","url":"https://www.hashicorp.com/blog/category/vault"}],"affected":[{"package":{"name":"github.com/hashicorp/vault","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.0"},{"fixed":"1.3.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-25xj-89g5-fm6h/GHSA-25xj-89g5-fm6h.json"}},{"package":{"name":"github.com/hashicorp/vault","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.4.0"},{"fixed":"1.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-25xj-89g5-fm6h/GHSA-25xj-89g5-fm6h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}