Impact
The consul-template library contains an information disclosure flaw in its error handling path that can cause Vault secret values to be included in template error messages, log output, and downstream surfaces such as Nomad task events. This weakness, identified as CWE‑532, results in a confidentiality breach wherein sensitive secrets intended for secure storage may be inadvertently exposed to unintended recipients.
Affected Systems
The vulnerability affects the HashiCorp Consul‑Template tool. No specific affected versions are listed, but the issue is resolved in consul‑template version 0.43.0. Administrators should verify the version of consul‑template in use against this fixed release.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves triggering error conditions during template processing, which would expose secret values via log files or event streams. No public exploitation is reported, but the potential for secret leakage warrants proactive remediation.
OpenCVE Enrichment