CVE-2021-32074
07.05.2021, 05:15
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault-action | 0.1.0 ≤ 𝑥 < 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References