Описание
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
Ссылки
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.1.0 (включая) до 2.2.0 (исключая)
cpe:2.3:a:hashicorp:vault-action:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00346
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Vault GitHub Action did not correctly mask multi-line secrets in output
EPSS
Процентиль: 57%
0.00346
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532