GHSA-22w5-2fxg-vrwx: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
When OpenTofu performs requests against an untrusted (or compromised) third-party server or connects to an attacker-controlled server, the initial connection negotiation can produce high CPU usage, leading to possible denial of service.
These vulnerabilities do not permit arbitrary code execution or allow disclosure of confidential information.
References
- github.com/advisories/GHSA-22w5-2fxg-vrwx
- github.com/opentofu/opentofu/issues/4242
- github.com/opentofu/opentofu/issues/4243
- github.com/opentofu/opentofu/issues/4244
- github.com/opentofu/opentofu/releases/tag/v1.11.9
- github.com/opentofu/opentofu/releases/tag/v1.12.2
- github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx
Code Behaviors & Features
Detect and mitigate GHSA-22w5-2fxg-vrwx with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →