First published: Fri Mar 26 2021(Updated: )
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Terraform Enterprise | <=202102-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3153 is medium with a severity value of 6.5.
HashiCorp Terraform Enterprise up to v202102-2 is affected by CVE-2021-3153.
CVE-2021-3153 has been fixed in v202103-1 of HashiCorp Terraform Enterprise.
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce the organization-level setting that required users to have two-factor authentication enabled.
You can find more information about CVE-2021-3153 at the following link: https://discuss.hashicorp.com/t/hcsec-2021-06-terraform-enterprise-organization-level-mfa-requirement-was-not-enforced/22401