Consul Template Vault Secret Exposure Before 0.29.2
CVE-2022-38149 Published on August 17, 2022
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
Products Associated with CVE-2022-38149
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-38149 are published in HashiCorp Consul Template:
Exploit Probability
EPSS
0.44%
Percentile
62.82%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.