{"id":"GHSA-4mgv-m5cm-f9h7","summary":"Vault GitHub Action did not correctly mask multi-line secrets in output","details":"HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.\n\nThe vault-action implementation did not correctly handle the marking of multi-line variables. As a result, multi-line secrets were not correctly masked in vault-action output.\n\nRemediation:\nCustomers using vault-action should evaluate the risk associated with this issue, and consider upgrading to vault-action 2.2.0 or newer. Please refer to https://github.com/marketplace/actions/hashicorp-vault for more information.","aliases":["CVE-2021-32074"],"modified":"2024-01-25T19:58:46Z","published":"2022-05-24T19:01:50Z","database_specific":{"nvd_published_at":"2021-05-07T05:15:00Z","cwe_ids":["CWE-532"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-29T19:57:46Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32074"},{"type":"WEB","url":"https://github.com/hashicorp/vault-action/issues/205"},{"type":"WEB","url":"https://github.com/hashicorp/vault-action/pull/208"},{"type":"WEB","url":"https://github.com/hashicorp/vault-action/commit/3526e1be65cf8faf42d6088bc5da8bff596c718a"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2021-13-vault-github-action-did-not-correctly-mask-multi-line-secrets-in-output/24128"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault-action"},{"type":"WEB","url":"https://github.com/hashicorp/vault-action/blob/master/CHANGELOG.md"}],"affected":[{"package":{"name":"hashicorp/vault-action","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4mgv-m5cm-f9h7/GHSA-4mgv-m5cm-f9h7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}