DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8f8p-9hrp-c8xm

Published

Last updated

https://images.chainguard.dev/security/CGA-8f8p-9hrp-c8xm
Package

terraform-1.8

Latest Update
Not affected
Aliases
  • CVE-2019-19316
  • GHSA-h3p9-wrgx-82cm

Severity

7.5

High

CVSS V3

Summary

Use of a Broken or Risky Cryptographic Algorithm in Terraform

Description

When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.

Specific Go Packages Affected

github.com/hashicorp/terraform/backend/remote-state/azure

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images