Exposure of Sensitive Information Through Environmental Variables
CVE-2019-14802
Summary
HashiCorp Nomad 0.5.0 through 0.9.4 reveals unintended environment variables to the rendering task during template rendering. This applies to "nomad/client/allocrunner/taskrunner/template".
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-526 - Exposure of Sensitive Information Through Environmental Variables
Environmental variables may contain sensitive information about a remote server.
References
Advisory Timeline
- Published