CVE-2022-38149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
17/08/2022
Last modified:
01/09/2022

Description

HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:consul_template:*:*:*:*:*:*:*:* 0.29.2 (excluding)