First published: Tue Aug 16 2022(Updated: )
A vulnerability was found in the HashiCorp Consul Template. This issue may reveal the contents of a Vault secret when used with an invalid template.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul Template | <0.29.2 | |
redhat/consul-template | <0.29.2 | 0.29.2 |
go/github.com/hashicorp/consul-template | >=0.29.0<0.29.2 | 0.29.2 |
go/github.com/hashicorp/consul-template | >=0.28.0<0.28.3 | 0.28.3 |
go/github.com/hashicorp/consul-template | <0.27.3 | 0.27.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-38149.
The severity of CVE-2022-38149 is high with a CVSS score of 7.5.
HashiCorp Consul Template versions up to 0.27.2, 0.28.2, and 0.29.1 are affected by CVE-2022-38149.
To fix CVE-2022-38149, update HashiCorp Consul Template to version 0.29.2 or higher.
Yes, you can find references for CVE-2022-38149 at the following links: [Reference 1](https://access.redhat.com/errata/RHSA-2023:3742), [Reference 2](https://access.redhat.com/security/cve/cve-2022-38149), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi?id=2119551).