{"id":"GO-2022-0980","summary":"Exposure of Vault secrets via error messages in github.com/hashicorp/consul-template","details":"The text of errors returned by Template.Execute can contain Vault secrets, potentially revealing these secrets in logs or error reports.","aliases":["CVE-2022-38149","GHSA-8449-7gc2-pwrp"],"modified":"2024-05-20T16:03:47Z","published":"2022-09-21T15:10:27Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2022-0980"},"references":[{"type":"ADVISORY","url":"https://discuss.hashicorp.com/t/hsec-2022-16-consul-template-may-expose-vault-secrets-when-processing-invalid-input/43215"},{"type":"FIX","url":"https://github.com/hashicorp/consul-template/commit/d6a6f4af219c28e67d847ba0e0b2bea8f5bb9076"}],"affected":[{"package":{"name":"github.com/hashicorp/consul-template","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/consul-template"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.27.3"},{"introduced":"0.28.0"},{"fixed":"0.28.3"},{"introduced":"0.29.0"},{"fixed":"0.29.2"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/hashicorp/consul-template/template","symbols":["Template.Execute"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0980.json"}}],"schema_version":"1.7.3"}