GHSA-65g2-x53q-cmf6
Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform
Quick fix
GHSA-65g2-x53q-cmf6 — kitchen-terraform: upgrade to the fixed version with the command below.
bundle update kitchen-terraformDetails
### Summary
Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the `info` logging level during the `kitchen converge` action. Prior to v7.0.0, the output values were printed at the `debug` level to avoid writing sensitive values to the terminal by default.
### Original Report
@brettcurtis: > Hopefully, I'm not doing something stupid here, but I'm seeing sensitive outputs printed in the kitchen output. You can check this action for an example: https://github.com/osinfra-io/terraform-google-project/actions/runs/4700065515/jobs/8334277309#step:5:215 > > It's not really a sensitive value just used it as an example.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/newcontext-oss/kitchen-terraform/security/advisories/GHSA-65g2-x53q-cmf6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-30618[ADVISORY]
- https://github.com/newcontext-oss/kitchen-terraform/commit/3d20d60e7a891e2dd747df995a31226fa0b4ac48[WEB]
- https://github.com/newcontext-oss/kitchen-terraform[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/kitchen-terraform/CVE-2023-30618.yml[WEB]