PT-2026-21856 · Tfplan2Md · Tfplan2Md

Oocx

·

Publicado

2026-02-25

·

Atualizado

2026-03-04

·

CVE-2026-27640

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions tfplan2md versions prior to 1.26.1
Description tfplan2md is software used to convert Terraform plan JSON files into Markdown reports. Versions of the software prior to 1.26.1 had a flaw where sensitive values that should have been masked as "(sensitive)" were instead rendered in plain text in several rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This resulted in potential exposure of sensitive data.
Recommendations Update to version 1.26.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27640
GHSA-5J8R-G94Q-2F39

Produtos afetados

Tfplan2Md