opentofu是opentofu组织的一款基础设施即代码工具。 opentofu 1.11.7之前版本存在后置链接漏洞,该漏洞源于初始化期间未能验证提供程序缓存目录中的现有符号链接,可能导致攻击者在受信任的工作目录中放置恶意符号链接,使tofu init将提供程序包内容写入工作目录之外的任意文件系统位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58375 | 7.5 HIGH | OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation |
| CVE-2026-74797 | 3.1 LOW | OpenTofu before 1.11.4 Denial of Service via malicious zip |
No comments yet