CVE-2021-36230

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/07/2021
Last modified:
29/07/2021

Description

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:terraform:*:*:*:*:*:enterprise:*:* 202107-1 (excluding)