terraformGHSA-h3p9-wrgx-82cm
Use of a Broken or Risky Cryptographic Algorithm in Terraform
High7.5CVE-2019-19316 · Published May 18, 2021 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/terraform Go | < 0.12.17 | 0.12.17 |
Details and references
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. ### Specific Go Packages Affected github.com/hashicorp/terraform/backend/remote-state/azure
More terraform advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 82023 | Terraform allows arbitrary file write during the `init` operation CVE-2023-4782Medium6.3fixed in 1.5.7 | Medium6.3 | 1.5.7 |