CVE-2021-36230: High severity terraform vulnerability
Published Jul 20, 2021
·Updated
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
Affected Software
1 affected component
Hashicorp Terraform Enterprise<202107-1
Event History
Jul 20, 2021
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-36230.
2
What is the severity of CVE-2021-36230?
The severity of CVE-2021-36230 is high with a CVSS score of 8.8.
3
What software versions are affected by CVE-2021-36230?
HashiCorp Terraform Enterprise releases up to v202106-1 are affected by CVE-2021-36230.
4
What is the impact of CVE-2021-36230?
CVE-2021-36230 allows privilege escalation to organization owner.
5
How was CVE-2021-36230 fixed?
CVE-2021-36230 was fixed in v202107-1 of HashiCorp Terraform Enterprise.