github.com/hashicorp/terraform known bugs

go

4 known bugs in github.com/hashicorp/terraform, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

4
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
highany0.12.17
Use of a Broken or Risky Cryptographic Algorithm in Terraform
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. ### Specific Go Packages Affected github.com/hashicorp/terraform/backend/remote-state/azure
fixedosv:GHSA-h3p9-wrgx-82cm
medium1.0.81.5.7
Terraform allows arbitrary file write during the `init` operation in github.com/hashicorp/terraform
Terraform allows arbitrary file write during the `init` operation in github.com/hashicorp/terraform
fixedosv:GO-2023-2055
mediumany0.12.17
Use of a Broken or Risky Cryptographic Algorithm in Terraform in github.com/hashicorp/terraform
Use of a Broken or Risky Cryptographic Algorithm in Terraform in github.com/hashicorp/terraform
fixedosv:GO-2022-0839
medium1.0.81.5.7
Terraform allows arbitrary file write during the `init` operation
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
fixedosv:GHSA-h626-pv66-hhm7
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/go/github.com/hashicorp/terraform
github.com/hashicorp/terraform bugs — known issues per version | DepScope | DepScope