PT-2024-32397 · Unknown · Power Platform Terraform Provider
Mattdot
·
Published
2024-09-25
·
Updated
2024-10-03
·
CVE-2024-47083
CVSS v4.0
8.8
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Power Platform Terraform Provider versions prior to 3.0.0
Description
The Power Platform Terraform Provider has an issue where sensitive information, specifically the
client secret used in the service principal authentication, may be exposed in logs due to an error in the logging code. This exposure occurs when logs are persisted or viewed, causing the client secret to not be properly masked. Users should upgrade to version 3.0.0 to receive a patched version of the provider that removes all logging of sensitive content. To mitigate the risk, users who have used this provider with the affected versions should immediately rotate the client secret for any service principal that has been configured using this Terraform provider.Recommendations
Upgrade to version 3.0.0 to receive a patched version of the provider.
Immediately rotate the
client secret for any service principal that has been configured using this Terraform provider.
Consider disabling the TF LOG PATH environment variable or Terraform log persistence to a file or an external system until a fixed version of the provider is updated.
Remove or sanitize existing logs that may contain the client secret to prevent unauthorized access.Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Power Platform Terraform Provider