CVE-2021-30476: Critical severity hashicorp terraform vulnerability
Published Apr 22, 2021
·Updated
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
Affected Software
1 affected component
HashiCorp Terraform Provider Vault<2.19.1
Remediation
Event History
Apr 22, 2021
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30476?
CVE-2021-30476 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-30476?
To fix CVE-2021-30476, upgrade to HashiCorp Terraform’s Vault Provider version 2.19.1 or later.
3
What is the impact of CVE-2021-30476?
CVE-2021-30476 allows incorrect configuration of GCE-type bound labels which can lead to unauthorized access.
4
Which version of HashiCorp Terraform’s Vault Provider is affected by CVE-2021-30476?
Versions prior to 2.19.1 of HashiCorp Terraform’s Vault Provider are affected by CVE-2021-30476.
5
Is CVE-2021-30476 specific to any cloud provider?
Yes, CVE-2021-30476 specifically affects the Google Cloud Platform (GCP) authentication method.