WhisperX tag archive

#log-leak

This page collects WhisperX intelligence signals tagged #log-leak. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-28 02:26:49 · GitHub Issues

1. OpenBao Secrets Operator Exposes Sensitive HTTP Credentials in Logs via GO-2024-2947

A reachable vulnerability in the OpenBao Secrets Operator's main branch is leaking sensitive HTTP basic authentication credentials directly into log files. The flaw, tracked as GO-2024-2947, stems from a failure to sanitize URLs before they are written to logs within the underlying `github.com/hashicorp/go-retryablehtt...

The Lab · 2026-04-01 04:27:01 · GitHub Issues

2. OpenBao Secrets Operator Exposed: GO-2024-2947 Vulnerability Leaks Sensitive Auth Credentials to Logs

A confirmed, reachable vulnerability in the OpenBao Secrets Operator's main branch risks leaking sensitive HTTP basic authentication credentials directly into log files. The security flaw, identified as GO-2024-2947, stems from a failure to sanitize URLs before they are written to logs within the `github.com/hashicorp/...