OpenTofu v1.11.14

v1.11.14
Security 2
  • Fix credentials being incorrectly resent to HTTP redirect targets when interacting with OCI Distribution registries for module or provider package installation
  • Fix potential high CPU usage and high memory usage in tofu init when resolving crafted relative URLs in API responses from attacker-controlled remote state backends or provider/module registries

From OpenTofu

SECURITY ADVISORIES:
  • When interacting with OCI Distribution registries for module or provider package installation, previous versions of OpenTofu could incorrectly resend credentials intended for the original origin to the target of an HTTP redirect. (#4423)
  • When interacting with an attacker-controlled remote state backend or provider/module registry, tofu init in earlier versions of OpenTofu could potentially cause high CPU usage and/or high memory usage resolving crafted relative URLs in the API responses. (#4473)

[!NOTE] This is the final patch release planned for the OpenTofu v1.11 series. We recommend upgrading to a newer release series as soon as possible.

Full Changelog: https://github.com/opentofu/opentofu/compare/v1.11.13...v1.11.14

View original

Upgraded? How did it go?

Discussion