HIGH 8.7 NVD
CVE-2024-58375
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, ve
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.
References
- https://github.com/opentofu/opentofu/security/advisories/GHSA-wpr2-j6gr-pjw9
- https://www.vulncheck.com/advisories/opentofu-before-secret-variable-leaking-via-static-ev
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-16 via NVD.
vulnfeed aggregates 11848 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.