以下是该漏洞描述的中文翻译: hashi-vault-js 是一个用于与 HashiCorp Vault API 进行交互的 Node.js 模块。在 0.5.2 版本之前, 中的所有 API 方法都会将失败的请求通过 函数处理,该函数会重新抛出原始的 ,并保留其 属性以及相应的响应配置。这些对象可能包含 请求头以及 中的请求体,其中包括提交的密码或机密值。如果使用该模块的应用程序通过控制台日志、结构化日志记录器、监控系统、崩溃报告或应用程序性能监控服务来记录捕获的异常,那么活跃的 Vault 令牌和请求中的机密信
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kyndryl-open-source | hashi-vault-js | < 0.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kyndryl-open-source | hashi-vault-js | < 0.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet