GHSA-4mgv-m5cm-f9h7

    Dashboard / Vulnerabilities / GHSA-4mgv-m5cm-f9h7

    GHSA-4mgv-m5cm-f9h7

    Published: 24 May 2022Last Modified: 25 Jan 2024

    Summary: Vault GitHub Action did not correctly mask multi-line secrets in output

    Details: HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking. The vault-action implementation did not correctly handle the marking of multi-line variables. As a result, multi-line secrets were not correctly masked in vault-action output. Remediation: Customers using vault-action should evaluate the risk associated with this issue, and consider upgrading to vault-action 2.2.0 or newer. Please refer to https://github.com/marketplace/actions/hashicorp-vault for more information.

    Affected packages

    Package

    Name: hashicorp/vault-action

    Purl:

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.2.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4mgv-m5cm-f9h7 | CVE-DB