Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13240 | Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20. |
Github GHSA |
GHSA-gcqf-f89c-68hv | Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 31 Dec 2025 10:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openbao
Openbao openbao |
|
| CPEs | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbao
Openbao openbao |
Tue, 12 Aug 2025 10:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
Mon, 14 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 22:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 May 2025 23:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 03 May 2025 00:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20. | |
| Title | Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-05-08T13:01:48.440Z
Reserved: 2025-04-30T21:43:10.413Z
Link: CVE-2025-4166
Updated: 2025-05-02T15:39:56.629Z
Status : Analyzed
Published: 2025-05-02T15:15:50.313
Modified: 2025-12-31T00:49:39.840
Link: CVE-2025-4166
OpenCVE Enrichment
Updated: 2025-06-24T18:44:17Z
EUVD
Github GHSA