Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform
Low severity
GitHub Reviewed
Published
Apr 21, 2023
in
newcontext-oss/kitchen-terraform
•
Updated Nov 6, 2023
Description
Published by the National Vulnerability Database
Apr 21, 2023
Published to the GitHub Advisory Database
Apr 24, 2023
Reviewed
Apr 24, 2023
Last updated
Nov 6, 2023
Summary
Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the
info
logging level during thekitchen converge
action. Prior to v7.0.0, the output values were printed at thedebug
level to avoid writing sensitive values to the terminal by default.Original Report
@brettcurtis:
References