Skip to content
opentofuGHSA-wpr2-j6gr-pjw9

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8

Low3.7CVE-2024-58375 · Published Oct 3, 2024 · updated Aug 17, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/opentofu/opentofu
Go
>= 1.8.0, < 1.8.31.8.3
Details and references

### Impact Users who have opted into static evaluation of module sources, versions, and backend configurations may be at risk of exposing sensitive variables and locals. This is a workflow that should not be possible and explicitly show errors. ### Workarounds Check that you are not using sensitive variables in module sources and versions, as well as backend configurations. The patch will add explicit errors and prevent this from being possible. ### Examples ```hcl variable "backend_path" { type = string sensitive = true } terraform { backend "local" { path = var.backend_path } } ``` ```hcl variable "mod_info" { type = string sensitive = true } module "foo" { source = var.mod_info //version = var.mod_info } ```

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
CVE-2024-58375, GO-2024-3182

More opentofu advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.