aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-03-27T18:00:00
Updated: 2024-08-05T07:10:47.407Z
Reserved: 2018-03-27T00:00:00
Link: CVE-2018-9057
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-03-27T18:29:00.307
Modified: 2024-11-21T04:14:53.183
Link: CVE-2018-9057
Redhat
No data.