CRITICAL9.8
GHSA-r48h-jr2j-9g78
HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG
Quick fix
GHSA-r48h-jr2j-9g78 — github.com/hashicorp/terraform-provider-aws: upgrade to the fixed version with the command below.
go get github.com/hashicorp/terraform-provider-aws@v1.14.0Details
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/terraform-provider-aws
Introduced in:
0Fixed in: 1.14.0Fix
go get github.com/hashicorp/terraform-provider-aws@v1.14.0References
- https://nvd.nist.gov/vuln/detail/CVE-2018-9057[ADVISORY]
- https://github.com/hashicorp/terraform-provider-aws/pull/3934[WEB]
- https://github.com/hashicorp/terraform-provider-aws/pull/3989[WEB]
- https://github.com/terraform-providers/terraform-provider-aws/pull/3934[WEB]
- https://github.com/hashicorp/terraform-provider-aws/commit/efa8cd45c6484ff70b2a515ea7ff06f2459d4ddf[WEB]
- https://github.com/hashicorp/terraform-provider-aws[PACKAGE]
- https://github.com/hashicorp/terraform-provider-aws/blob/02b039aa82dd7fc6e4a97a0922cc5dbbab724021/resource_aws_iam_user_login_profile.go#L70-L80[WEB]