First published: Thu Jul 30 2020(Updated: )
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Terraform Enterprise | <202007-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-15511.
The severity of CVE-2020-15511 is medium with a severity value of 5.3.
The affected software is HashiCorp Terraform Enterprise up to v202006-1.
CVE-2020-15511 allows user registration on the default signup page even when disabled, bypassing SAML enforcement.
CVE-2020-15511 was fixed in v202007-1 of HashiCorp Terraform Enterprise.