CVE-2021-3153: Medium severity Hashicorp Terraform Enterprise vulnerability
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v202103-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3153?
The severity of CVE-2021-3153 is medium with a severity value of 6.5.
What software versions are affected by CVE-2021-3153?
HashiCorp Terraform Enterprise up to v202102-2 is affected by CVE-2021-3153.
What is the fix for CVE-2021-3153?
CVE-2021-3153 has been fixed in v202103-1 of HashiCorp Terraform Enterprise.
Is two-factor authentication required for users within an organization in HashiCorp Terraform Enterprise?
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce the organization-level setting that required users to have two-factor authentication enabled.
Where can I find more information about CVE-2021-3153?
You can find more information about CVE-2021-3153 at the following link: https://discuss.hashicorp.com/t/hcsec-2021-06-terraform-enterprise-organization-level-mfa-requirement-was-not-enforced/22401