Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2024-58375

CVE-2024-58375: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.9

    Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation

    CVE-2024-58375Source published Source updated

    OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts. A flaw was found in OpenTofu. This oversight can lead to the exposure of values intended to be sensitive through these configuration elements, resulting in an information disclosure vulnerability. While the vulnerability could expose sensitive variables, the attack complexity is high, requiring specific user configurations to be in place for exploitation. Red…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • 1.8.0
    • 1.8.2
    Source-reported fixed versions
    • 1.8.3
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery