HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-6511 HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
Github GHSA Github GHSA GHSA-8449-7gc2-pwrp HashiCorp Consul Template could reveal Vault secret contents in error messages
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T10:45:52.674Z

Reserved: 2022-08-11T00:00:00

Link: CVE-2022-38149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-17T15:15:08.607

Modified: 2024-11-21T07:15:53.740

Link: CVE-2022-38149

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-08-16T00:00:00Z

Links: CVE-2022-38149 - Bugzilla

cve-icon OpenCVE Enrichment

No data.