Bug 1158440 (CVE-2019-19316) - VUL-0: CVE-2019-19316: terraform: possibility of transferring SAS token in cleartext
Summary: VUL-0: CVE-2019-19316: terraform: possibility of transferring SAS token in cl...
Status: RESOLVED FIXED
Alias: CVE-2019-19316
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: John Paul Adrian Glaubitz
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/248225/
Whiteboard: CVSSv2:NVD:CVE-2019-19316:4.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-12-04 15:09 UTC by Alexandros Toptsoglou
Modified: 2022-10-05 11:46 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-12-04 15:09:28 UTC
CVE-2019-19316

When using the Azure backend with a shared access signature (SAS), Terraform
versions prior to 0.12.17 may transmit the token and state snapshot using
cleartext HTTP.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19316
https://github.com/hashicorp/terraform/security/advisories/GHSA-4rvg-555h-r626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19316
Comment 1 Klaus Kämpf 2019-12-04 15:51:34 UTC
CaaSP does not support Azure (yet)
Comment 2 Klaus Kämpf 2019-12-04 15:54:13 UTC
/cc public cloud
Comment 3 John Paul Adrian Glaubitz 2020-01-20 10:01:49 UTC
Submitted the update to 0.12.19 as MR#209682. Did some basic testing before submitting.
Comment 5 Swamp Workflow Management 2020-02-04 20:11:11 UTC
SUSE-SU-2020:0320-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1158440
CVE References: CVE-2019-19316
Sources used:
SUSE Linux Enterprise Module for Public Cloud 15-SP1 (src):    terraform-0.12.19-3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 OBSbugzilla Bot 2020-06-09 17:30:09 UTC
This is an autogenerated message for OBS integration:
This bug (1158440) was mentioned in
https://build.opensuse.org/request/show/813002 Factory / terraform
Comment 9 John Paul Adrian Glaubitz 2022-10-05 11:46:47 UTC
Released.