Описание
Security update for terraform
This update for terraform to version 0.12.19 fixes the following issues:
- CVE-2019-19316: Fixed an information leak where SAS token could be transfered in cleartext (bsc#1158440).
Список пакетов
SUSE Linux Enterprise Module for Public Cloud 15 SP1
terraform-0.12.19-3.6.1
Ссылки
- Link for SUSE-SU-2020:0320-1
- E-Mail link for SUSE-SU-2020:0320-1
- SUSE Security Ratings
- SUSE Bug 1158440
- SUSE CVE CVE-2019-19316 page
Описание
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.
Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15 SP1:terraform-0.12.19-3.6.1
Ссылки
- CVE-2019-19316
- SUSE Bug 1158440