This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Infrastructure as Code
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates BUG FIXES, SECURITY ADVISORIES, and Advisory across a mixed release.
Full changelog
BUG FIXES:
- Properly handle
TF_ENCRYPTIONwith only blank spaces. (#4265) - The value resulted from the
lifecycle.enabledevaluation now has its deprecation marks processed correctly (#4162) - Update documentation to clarify the usage restriction of ephemeral values in
lifecycle.enabled. (#4220) tofu console -lock=falsenow works as intended. (#4291)
SECURITY ADVISORIES:
- Previous releases in the v1.12 series could read an arbitrary file during certain git operations via a maliciously crafted URL (#4293)
- Advisory: https://github.com/opentofu/opentofu/security/advisories/GHSA-q7j3-v8qv-22vq
Full Changelog: https://github.com/opentofu/opentofu/compare/v1.12.2...v1.12.3
Security Fixes
- GHSA-q7j3-v8qv-22vq — previous v1.12 releases could read arbitrary files during certain git operations via a maliciously crafted URL
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Earlier breaking changes
- v1.12.0 Removal of OPENTOFU_USER_AGENT environment variable affects custom User-Agent header behavior.
Beta — feedback welcome: [email protected]