HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG
Critical severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 21, 2024
Package
Affected versions
< 1.14.0
Patched versions
1.14.0
Description
Published by the National Vulnerability Database
Mar 27, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 21, 2024
Last updated
Feb 21, 2024
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
References