Cleartext transmission of sensitive information in Terraform - CVE-2019-19316
Published: December 9, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists in the "github.com/hashicorp/terraform/tree/master/backend/remote-state/azure" due to software uses insecure communication channel to transmit sensitive information when using the Azure backend with a shared access signature (SAS). A remote attacker with ability to intercept network traffic can gain access to sensitive data, such as the token and state snapshot.
Affected software
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2019-19316
IBM Cloud Pak for Watson AIOps - update to 4.2.1