CVE-2021-40862: Infoleak
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Terraform Enterpriseto a version that resolves this vulnerability.Fixed in v202109-1
Event History
Frequently Asked Questions
What is CVE-2021-40862?
CVE-2021-40862 is a vulnerability in HashiCorp Terraform Enterprise up to v202108-1 that exposes a sensitive URL to authenticated users.
What is the severity of CVE-2021-40862?
CVE-2021-40862 has a severity rating of 8.8 (high).
How does CVE-2021-40862 impact HashiCorp Terraform Enterprise?
CVE-2021-40862 can be exploited by authenticated users to perform privilege escalation or unauthorized modification of a Terraform configuration.
What is the fix for CVE-2021-40862?
CVE-2021-40862 is fixed in version v202109-1 of HashiCorp Terraform Enterprise.
Where can I find more information about CVE-2021-40862?
You can find more information about CVE-2021-40862 in the following link: [HashiCorp Discuss](https://discuss.hashicorp.com/t/hcsec-2021-25-terraform-enterprise-configuration-versions-api-discloses-sensitive-url/29508)