Skip to main content

Exposure of Sensitive Information Through Environmental Variables

CVE-2019-14802

Severity Medium
Score 5.3/10

Summary

HashiCorp Nomad 0.5.0 through 0.9.4 reveals unintended environment variables to the rendering task during template rendering. This applies to "nomad/client/allocrunner/taskrunner/template".

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-526 - Exposure of Sensitive Information Through Environmental Variables

Environmental variables may contain sensitive information about a remote server.

Advisory Timeline

  • Published