The vendor explicitly states that these products are not affected by this CVE.
- hi/opentofu as a component of Red Hat Hardened Images
- opentofu1.10.src as a component of Red Hat Hardened Images
- opentofu1.11.src as a component of Red Hat Hardened Images
- opentofu1.12.src as a component of Red Hat Hardened Images
- Summary
- A flaw was found in OpenTofu. When users enable static evaluation of module sources, versions, and backend configurations, the software does not properly restrict sensitive variables and locals. This oversight can lead to the exposure of values intended to be sensitive through these configuration elements, resulting in an information disclosure vulnerability.
- Remediation
- No remediation text is recorded.
