PT-2024-32397 · Unknown · Power Platform Terraform Provider

Mattdot

·

Published

2024-09-25

·

Updated

2024-10-03

·

CVE-2024-47083

CVSS v4.0

8.8

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Power Platform Terraform Provider versions prior to 3.0.0
Description The Power Platform Terraform Provider has an issue where sensitive information, specifically the client secret used in the service principal authentication, may be exposed in logs due to an error in the logging code. This exposure occurs when logs are persisted or viewed, causing the client secret to not be properly masked. Users should upgrade to version 3.0.0 to receive a patched version of the provider that removes all logging of sensitive content. To mitigate the risk, users who have used this provider with the affected versions should immediately rotate the client secret for any service principal that has been configured using this Terraform provider.
Recommendations Upgrade to version 3.0.0 to receive a patched version of the provider. Immediately rotate the client secret for any service principal that has been configured using this Terraform provider. Consider disabling the TF LOG PATH environment variable or Terraform log persistence to a file or an external system until a fixed version of the provider is updated. Remove or sanitize existing logs that may contain the client secret to prevent unauthorized access.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47083
GHSA-7W3W-PJM5-M36C

Affected Products

Power Platform Terraform Provider