Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpr2-j6gr-pjw9

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.9
CVSS3: 3.7

Описание

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8

Impact

Users who have opted into static evaluation of module sources, versions, and backend configurations may be at risk of exposing sensitive variables and locals. This is a workflow that should not be possible and explicitly show errors.

Workarounds

Check that you are not using sensitive variables in module sources and versions, as well as backend configurations. The patch will add explicit errors and prevent this from being possible.

Examples

variable "backend_path" { type = string sensitive = true } terraform { backend "local" { path = var.backend_path } }
variable "mod_info" { type = string sensitive = true } module "foo" { source = var.mod_info //version = var.mod_info }

Пакеты

Наименование

github.com/opentofu/opentofu

go
Затронутые версииВерсия исправления

>= 1.8.0, < 1.8.3

1.8.3

2.9 Low

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-200

2.9 Low

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-200