Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-30618

16
FAUCET Score

CVE-2023-30618 is a regression in Kitchen-Terraform v7.0.0 that causes sensitive Terraform output values to be logged at the 'info' level during 'kitchen converge', making them visible in standard logs. This vulnerability has a low severity CVSS score of 3.3, requiring local access to the affected machine to view the logs and potentially expose sensitive information. There are no known active exploits, public exploit code, or significant community discussion surrounding this issue. Users are advised to upgrade to a patched version as no workarounds exist.

Impacted Technologies

VendorProductVersion(s)CPE
7.0.0CPE matchmatch criteria
cpe:2.3:a:kitchen-terraform_project:kitchen-terraform:7.0.0:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

3.2LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.5
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 52nd percentile among its peer group of 1,509 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: kitchen-terraformFixed in: 7.0.1

Vendor Advisories (1)

rubygemsGHSA-65g2-x53q-cmf6low

Sensitive Terraform Output Values Printed At Info Logging Level In Kitchen-Terraform

Apr 24, 2023

References

github.com / newcontext-oss/kitchen-terraform/commit/3d20d60e7a891e2dd747df995a31226fa0b4ac48
Patch
github.com / newcontext-oss/kitchen-terraform/security/advisories/GHSA-65g2-x53q-cmf6
Third Party Advisory