{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/opentofu/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-58375"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenTofu (1.8.0-1.8.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenTofu"],"content_html":"\u003cp\u003eOpenTofu versions 1.8.0 through 1.8.2 contain a vulnerability (CVE-2024-58375) regarding the handling of sensitive variables and local values. When users enable the static evaluation of module sources, versions, or backend configurations, the application fails to enforce the restriction of values marked as sensitive. Instead of throwing a validation error as intended, the system may leak these sensitive values through these configuration elements. This exposure could allow unauthorized access to sensitive secrets, credentials, or environment-specific data handled within infrastructure-as-code configurations. The issue is addressed in OpenTofu 1.8.3, which introduces mandatory validation errors to prevent the use of sensitive values in these contexts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in the exposure of sensitive secrets (e.g., API keys, passwords, or tokens) contained in configuration files. This data could be accessed by any actor with read access to the infrastructure code, logs, or state files, potentially leading to privilege escalation or further compromise of the integrated cloud environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit all OpenTofu configurations for instances where sensitive variables might be utilized in module sources, versions, or backend configurations.\u003c/li\u003e\n\u003cli\u003eUpgrade all instances of OpenTofu to version 1.8.3 or later to benefit from the implemented validation errors and prevent accidental leakage.\u003c/li\u003e\n\u003cli\u003eReview logs and version control history for infrastructure-as-code deployments using OpenTofu 1.8.0-1.8.2 to identify potential prior exposure of sensitive variables.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T14:25:46Z","date_published":"2026-08-16T14:25:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-opentofu-sensitive-leak/","summary":"OpenTofu versions 1.8.0 through 1.8.2 fail to correctly restrict sensitive variables during static evaluation, leading to the potential exposure of sensitive information in module and backend configurations.","title":"Sensitive Data Exposure in OpenTofu Static Evaluation","url":"https://feed.craftedsignal.io/briefs/2026-08-opentofu-sensitive-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenTofu","version":"https://jsonfeed.org/version/1.1"}