CVE-2019-19316: Input Validation
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19316?
The severity of CVE-2019-19316 is high (7.5).
How does CVE-2019-19316 affect Terraform versions?
CVE-2019-19316 affects Terraform versions prior to 0.12.17.
What is the vulnerability description of CVE-2019-19316?
CVE-2019-19316 allows the transmission of the token and state snapshot using cleartext HTTP when using the Azure backend with a shared access signature (SAS).
How can I remediate CVE-2019-19316?
To remediate CVE-2019-19316, upgrade Terraform to version 0.12.17 or above.
Are there any references for CVE-2019-19316?
Yes, you can find references for CVE-2019-19316 at: [GitHub Advisory](https://github.com/hashicorp/terraform/security/advisories/GHSA-4rvg-555h-r626), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19316), [GitHub Issue](https://github.com/hashicorp/terraform/issues/23493).