First published: Tue Jul 20 2021(Updated: )
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Terraform | <202107-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-36230.
The severity of CVE-2021-36230 is high with a CVSS score of 8.8.
HashiCorp Terraform Enterprise releases up to v202106-1 are affected by CVE-2021-36230.
CVE-2021-36230 allows privilege escalation to organization owner.
CVE-2021-36230 was fixed in v202107-1 of HashiCorp Terraform Enterprise.