CVE-2021-32074: High severity hashicorp vault vulnerability
Published May 7, 2021
·Updated
HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.
Affected Software
2 affected componentsFixes available
actions/hashicorp/vault-action<2.2.0
2.2.0
HashiCorp vault-action>=0.1.0<2.2.0
Remediation
Patch Available
Event History
May 7, 2021
CVE Published
via MITRE·04:01 AM
Data Sourced
via MITRE·04:01 AM
Description
May 24, 2022
Advisory Published
via GitHub·07:01 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-32074?
CVE-2021-32074 is classified as a high severity vulnerability due to the potential exposure of sensitive information from log files.
2
How do I fix CVE-2021-32074?
To fix CVE-2021-32074, update the HashiCorp vault-action to version 2.2.0 or later.
3
What types of sensitive information are affected by CVE-2021-32074?
CVE-2021-32074 can expose multi-line secrets stored in GitHub Actions log files.
4
Is CVE-2021-32074 specific to any particular version of the HashiCorp vault-action?
Yes, CVE-2021-32074 affects all versions of HashiCorp vault-action before 2.2.0.
5
Can CVE-2021-32074 be exploited remotely?
Yes, CVE-2021-32074 can be exploited remotely by attackers who have access to the GitHub Actions logs.