DirectorySecurity Advisories
Sign In
Security Advisories

CGA-4fvw-86mv-qrv4

Published

Last updated

https://images.chainguard.dev/security/CGA-4fvw-86mv-qrv4
Package

terraform-provider-aws

Latest Update
Not affected
Aliases
  • CVE-2018-9057
  • GHSA-r48h-jr2j-9g78

Severity

9.8

Critical

CVSS V3

Summary

HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG

Description

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images