CVE-2024-56802

Severity CVSS v4.0:
HIGH
Type:
CWE-285 Improper Authorization
Publication date:
31/12/2024
Last modified:
31/12/2024

Description

Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.