PT-2026-21856 · Tfplan2Md · Tfplan2Md
Oocx
·
Publicado
2026-02-25
·
Atualizado
2026-03-04
·
CVE-2026-27640
CVSS v4.0
8.5
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
tfplan2md versions prior to 1.26.1
Description
tfplan2md is software used to convert Terraform plan JSON files into Markdown reports. Versions of the software prior to 1.26.1 had a flaw where sensitive values that should have been masked as "(sensitive)" were instead rendered in plain text in several rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This resulted in potential exposure of sensitive data.
Recommendations
Update to version 1.26.1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tfplan2Md