RSS   Vulnerabilities for 'Vault-action'   RSS

2021-05-07
 
CVE-2021-32074

CWE-532
 

 
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.

 

 >>> Vendor: Hashicorp 15 Products
Vagrant vmware fusion
Vagrant
Terraform
Consul
Nomad
Packer
Vault
Terraform enterprise
Vault-ssh-helper
Go-slug
Vault provider for secrets store csi driver
Terraform provider
Vault-action
Sentinel
Go-getter


Copyright 2024, cxsecurity.com

 

Back to Top