[1.83.5]
Update vault to 2.0.4
Full Changelog
containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps.
acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters/denied_parameters constraints.
core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed.
secrets: Added ability to view secrets in YAML format
auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener.
Proxy/Agent: Fixed a bug where auth method headers accumulated on the shared API client across re-auth cycles.
audit: Fix a regression from CVE-2025-6000 that broke enabling audit devices on Windows when a plugin directory was configured.
auth/cert: Add support for x-forwarded cert headers coming from AWS ALBs.
core: Preserve URL query parameters when redirecting API requests containing duplicate slashes to their canonical path. Previously, the redirect dropped parameters such as ?list=true, potentially changing the result of the request.
secrets-sync: Fix GCP Secret Manager destinations losing their per-region KMS key on Vault restart.