Cleartext transmission of sensitive information in Terraform - CVE-2019-19316

 

Cleartext transmission of sensitive information in Terraform - CVE-2019-19316

Published: December 9, 2019


Vulnerability identifier: #VU23455
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19316
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the "github.com/hashicorp/terraform/tree/master/backend/remote-state/azure" due to software uses insecure communication channel to transmit sensitive information when using the Azure backend with a shared access signature (SAS). A remote attacker with ability to intercept network traffic can gain access to sensitive data, such as the token and state snapshot.


Affected software

Terraform
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2019-19316

Install updates from vendor's website.

Terraform - update to 0.12.17
IBM Cloud Pak for Watson AIOps - update to 4.2.1

External References

Related Security Bulletins