Bugzilla – Bug 1158440
VUL-0: CVE-2019-19316: terraform: possibility of transferring SAS token in cleartext
Last modified: 2022-10-05 11:46:47 UTC
CVE-2019-19316 When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19316 https://github.com/hashicorp/terraform/security/advisories/GHSA-4rvg-555h-r626 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19316
CaaSP does not support Azure (yet)
/cc public cloud
Submitted the update to 0.12.19 as MR#209682. Did some basic testing before submitting.
SUSE-SU-2020:0320-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1158440 CVE References: CVE-2019-19316 Sources used: SUSE Linux Enterprise Module for Public Cloud 15-SP1 (src): terraform-0.12.19-3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
This is an autogenerated message for OBS integration: This bug (1158440) was mentioned in https://build.opensuse.org/request/show/813002 Factory / terraform
Released.