OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2024-58375 affects OpenTofu versions 1.8.0 through 1.8.2, where sensitive variables and locals are inadvertently exposed through static evaluation of module sources, versions, and backend configurations. This vulnerability is critical because infrastructure-as-code practitioners rely on sensitive value masking to prevent credential leakage in logs, state files, and configuration outputs. Organizations using affected OpenTofu versions risk exposing database passwords, API keys, and authentication tokens that should remain hidden, potentially compromising cloud infrastructure, CI/CD pipelines, and backend services. The vulnerability stems from insufficient input validation (CWE-497) when static evaluation is enabled, allowing sensitive data to bypass protective mechanisms designed to redact or reject such values.
While traditional MITRE ATT&CK mapping doesn't directly apply to this configuration management flaw, Casky's Claude-powered analysis would identify this as a credential exposure risk by examining infrastructure code patterns where sensitive values appear in contexts that should reject them—specifically module source declarations, version specifications, and backend blocks. Practitioners using Casky would see findings flagged for: (1) sensitive variables referenced in static evaluation contexts, (2) credentials persisting in configuration artifacts that typically expose values to version control or logs, and (3) backend configurations containing unmasked authentication material. The detection leverages extended reasoning to understand that even "static" configuration elements can become attack surfaces when sensitive data validation fails, connecting to broader reconnaissance and credential access patterns that adversaries exploit post-compromise.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2024-58375. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation