PT-2021-19654 · Hashicorp · Vault-Action
Kotyara85
·
Published
2021-05-07
·
Updated
2022-05-24
·
CVE-2021-32074
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
HashiCorp vault-action versions prior to 2.2.0
Description:
The issue allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking. This occurred due to the vault-action implementation not correctly handling the marking of multi-line variables, resulting in multi-line secrets not being correctly masked in vault-action output.
Recommendations:
For versions prior to 2.2.0, consider upgrading to vault-action 2.2.0 or newer to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of sensitive information exposure.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vault-Action