OpenTofu v1.12.6

v1.12.6
Security 2
  • Fix incorrect resending of credentials to HTTP redirect targets when interacting with OCI Distribution registries for module or provider package installation
  • Fix potential high CPU and memory usage in tofu init when resolving crafted relative URLs in API responses from attacker-controlled remote state backends or registries

From OpenTofu

SECURITY ADVISORIES:
  • When interacting with OCI Distribution registries for module or provider package installation, earlier versions of OpenTofu could incorrectly resend credentials intended for the original origin to the target of an HTTP redirect. (#4422)
  • When interacting with an attacker-controlled remote state backend or provider/module registry, tofu init in earlier versions of OpenTofu could potentially cause high CPU usage and/or high memory usage resolving crafted relative URLs in the API responses. (#4472)

Full Changelog: https://github.com/opentofu/opentofu/compare/v1.12.5...v1.12.6

View original

Upgraded? How did it go?

Discussion