MyHoard Backup Encryption Key Logging Vulnerability

Vulnerability

A vulnerability in MyHoard, a daemon for managing MySQL backups, allows the backup encryption key to be logged in plain text. This issue affects versions 1.0.1 through 1.2.9. The vulnerability arises because, in certain cases, MyHoard logs complete backup information, including sensitive encryption keys. While version 1.3.0 addresses this issue, users of earlier versions may inadvertently expose encryption keys in log files.

Impact

Logging of backup encryption keys in plain text, creating a risk of unauthorized access to encrypted backups.

Reproduction

The vulnerability can be reproduced by creating a backup with MyHoard version 1.0.1 through 1.2.9. In some cases, the backup logs will include the encryption key in plain text. This can be verified by checking the log files after the backup process.

Remediation

Users can upgrade to MyHoard version 1.3.0 or later, which addresses this vulnerability. Alternatively, logs can be directed to /dev/null to prevent sensitive information from being recorded.

Added: Dec 18, 2025, 7:17 PM
Updated: Dec 18, 2025, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
1.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.