CVE-2018-9057

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
References
Link Resource
https://github.com/terraform-providers/terraform-provider-aws/pull/3934 Issue Tracking Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:hashicorp:terraform:*:*:*:*:*:aws:*:*

Information

Published : 2018-03-27 11:29

Updated : 2018-04-24 05:08


NVD link : CVE-2018-9057

Mitre link : CVE-2018-9057


JSON object : View

CWE
CWE-332

Insufficient Entropy in PRNG

Advertisement

dedicated server usa

Products Affected

hashicorp

  • terraform