Skip to content
terraformGHSA-h3p9-wrgx-82cm

Use of a Broken or Risky Cryptographic Algorithm in Terraform

High7.5CVE-2019-19316 · Published May 18, 2021 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/terraform
Go
< 0.12.170.12.17
Details and references

When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. ### Specific Go Packages Affected github.com/hashicorp/terraform/backend/remote-state/azure

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-327
Also known as
CVE-2019-19316, GHSA-4rvg-555h-r626, GO-2022-0839

More terraform advisories

All
DateAdvisory
Sep 82023Terraform allows arbitrary file write during the `init` operation
CVE-2023-4782Medium6.3fixed in 1.5.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.