/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2018-9057

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2018-9057

CGA ID

CGA-4fvw-86mv-qrv4

Severity

Unknown

Description

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.

References

  • https://images.chainguard.dev/security/CGA-4fvw-86mv-qrv4

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs