CVE-2024-58375
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-497
- Published
- 2026-08-16
- Last modified
- 2026-08-17
Affected products
- opentofu opentofu
- opentofu opentofu
Weakness type
Related vulnerabilities
- CVE-2026-61911 — An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An...
- CVE-2026-81394 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-81387 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-69315 — Windows License Manager Information Disclosure Vulnerability
- CVE-2026-68842 — Windows MIDI Service Module Information Disclosure Vulnerability
- CVE-2026-71330 — Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- CVE-2026-69832 — Win32k Information Disclosure Vulnerability
- CVE-2026-69723 — Windows Kernel Information Disclosure Vulnerability