What is CVE-2024-58375?
The CVE-2024-58375 vulnerability affects OpenTofu versions 1.8.0 through 1.8.2, where sensitive variables and locals are not properly restricted when users enable static evaluation of module sources, versions, and backend configurations. This flaw can lead to exposure of marked sensitive values through these configuration elements. Affected users should immediately upgrade OpenTofu to the latest version or disable static evaluation.
Azərbaycanca: CVE-2024-58375 zəifliyi OpenTofu-nun 1.8.0-1.8.2 versiyalarında aşkarlanıb. Bu zəiflik istifadəçilər modul mənbələrinin, versiyalarının və arxa plan konfiqurasiyalarının statik qiymətləndirilməsini aktiv etdikdə sensitive kimi işarələnmiş dəyişənlərin ifşa olmasına səbəb olur. Təsirə məruz qalan istifadəçilər dərhal OpenTofu-nu ən son versiyaya yeniləməli və ya statik qiymətləndirməni deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which OpenTofu versions are affected by CVE-2024-58375?
The vulnerability affects OpenTofu versions 1.8.0, 1.8.1, and 1.8.2.
What actions should users take to mitigate CVE-2024-58375?
Users should upgrade OpenTofu to the latest version or disable the static evaluation feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.