Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HashiCorp Terraform Amazon Web Services provider 安全漏洞
Vulnerability Description
HashiCorp Terraform Amazon Web Services(AWS)provider是一款用于与AWS支持的资源进行交互的程序。 HashiCorp Terraform AWS provider 1.12.0及之前版本中的aws/resource_aws_iam_user_login_profile.go文件存在安全漏洞。远程攻击者可借助带有较弱密码的IAM账户利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A