FreeBSD : terraform -- exclusion bypass in .terraformignore handling (4496ae0c-9d7d-11f1-a655-3497f65b111b)

medium Nessus Plugin ID 338841

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 4496ae0c-9d7d-11f1-a655-3497f65b111b advisory.

HashiCorp reports:
Terraform bundles the go-slug library, which builds the archive uploaded to HCP Terraform or Terraform Enterprise when a run is started. In go-slug before v0.18.3, matching of .terraformignore rules does not consistently treat canonically equivalent Unicode filenames as the same path.
On filesystems that normalize filenames, a file whose displayed name appears to match an exclusion rule can still end up in the generated upload bundle, so local files an operator intended to keep out of remote runs may be transmitted.
Exploitation requires local control over the working directory contents, use of .terraformignore, and filenames and ignore patterns that differ only by Unicode normalization form. Setups that do not use .terraformignore, use ASCII-only filenames and patterns, or run on filesystems that do not perform this normalization are not affected.

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://github.com/hashicorp/terraform/releases/tag/v1.15.9

http://www.nessus.org/u?a2a88a51

http://www.nessus.org/u?c3c35fdd

Plugin Details

Severity: Medium

ID: 338841

File Name: freebsd_pkg_4496ae0c9d7d11f1a6553497f65b111b.nasl

Version: 1.1

Type: Local

Published: 8/22/2026

Updated: 8/22/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-14978

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:terraform

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2026

Vulnerability Publication Date: 8/19/2026

Reference Information

CVE: CVE-2026-14978