This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Infrastructure as Code
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
rce_ssrf
breaking_upgrade
Summary
AI summaryFixes arbitrary‑file disclosure vulnerability when processing malicious Git URLs.
Full changelog
BUG FIXES:
- Update documentation to clarify the usage restriction of ephemeral values in
lifecycle.enabled. (#4220)
SECURITY ADVISORIES:
- Previous releases in the v1.11 series could read an arbitrary file during certain git operations via a maliciously crafted URL (#4292).
- Advisory: https://github.com/opentofu/opentofu/security/advisories/GHSA-q7j3-v8qv-22vq
Full Changelog: https://github.com/opentofu/opentofu/compare/v1.11.9...v1.11.10
Security Fixes
- GHSA-q7j3-v8qv-22vq — previous v1.11 releases could read arbitrary files via malicious Git URLs
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Earlier breaking changes
- v1.12.0 Removal of OPENTOFU_USER_AGENT environment variable affects custom User-Agent header behavior.
Beta — feedback welcome: [email protected]