CVE-2020-15511: Medium severity terraform vulnerability
Published Jul 30, 2020
·Updated
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.
Affected Software
1 affected component
Hashicorp Terraform Enterprise<202007-1
Event History
Jul 30, 2020
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-15511.
2
What is the severity of CVE-2020-15511?
The severity of CVE-2020-15511 is medium with a severity value of 5.3.
3
What is the affected software?
The affected software is HashiCorp Terraform Enterprise up to v202006-1.
4
How does CVE-2020-15511 affect user registration?
CVE-2020-15511 allows user registration on the default signup page even when disabled, bypassing SAML enforcement.
5
How was CVE-2020-15511 fixed?
CVE-2020-15511 was fixed in v202007-1 of HashiCorp Terraform Enterprise.