Описание
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
A flaw was found in OpenTofu. A remote attacker could exploit this vulnerability by providing maliciously-crafted .zip archives during the tofu init command, which is used for provider or module package initialization. This could lead to excessive CPU usage, causing a Denial of Service (DoS) by degrading system performance and preventing the completion of the initialization process.
Отчет
This Low impact denial of service vulnerability in OpenTofu affects the tofu init command when processing maliciously-crafted .zip archives. Exploitation requires an attacker to provide a malicious archive, necessitating user interaction or a compromised dependency supply chain, which limits the attack surface in Red Hat environments where tofu init is typically executed in controlled development or CI/CD pipelines.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Hardened Images | hi/opentofu | Not affected | ||
| Red Hat Hardened Images | opentofu1.10 | Not affected | ||
| Red Hat Hardened Images | opentofu1.11 | Not affected | ||
| Red Hat Hardened Images | opentofu1.12 | Not affected |
Показывать по
Дополнительная информация
Статус:
3.1 Low
CVSS3
Связанные уязвимости
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
OpenTofu versions before 1.11.4 contain a denial of service vulnerabil ...
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
3.1 Low
CVSS3