July 14, 2023, 10:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from Weave GitOps Terraform Runners (`tf-runner`), where sensitive data is inadvertently printed - potentially revealing sensitive user data in their pod logs. In particular, functions `tfexec.ShowPlan`, `tfexec.ShowPlanRaw`, and `tfexec.Output` are implicated when the `tfexec` object set …

cve data gitops information resources runners sensitive data sensitive information terraform vulnerability

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Information Systems Security Manager (ISSM)

@ Avaya | Irving, TX, US

Senior Cloud Security Engineer

@ BMO | M3704 - BMO Place (33 Dundas West, Toronto, ON) - BMO

Junior DevSecOps Engineer

@ Dark Wolf Solutions | Tampa, FL

Offensive Security Engineer

@ Kaseya | Dundalk, Louth, Ireland