First published: Wed Sep 15 2021(Updated: )
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Terraform Enterprise | <=202108-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40862 is a vulnerability in HashiCorp Terraform Enterprise up to v202108-1 that exposes a sensitive URL to authenticated users.
CVE-2021-40862 has a severity rating of 8.8 (high).
CVE-2021-40862 can be exploited by authenticated users to perform privilege escalation or unauthorized modification of a Terraform configuration.
CVE-2021-40862 is fixed in version v202109-1 of HashiCorp Terraform Enterprise.
You can find more information about CVE-2021-40862 in the following link: [HashiCorp Discuss](https://discuss.hashicorp.com/t/hcsec-2021-25-terraform-enterprise-configuration-versions-api-discloses-sensitive-url/29508)