CVE-2022-25374: High severity terraform vulnerability
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25374?
CVE-2022-25374 is a vulnerability in HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 that allows sensitive data to be captured in log files.
What is the severity of CVE-2022-25374?
CVE-2022-25374 has a severity level of high, with a CVSS score of 7.5.
How can CVE-2022-25374 impact me?
CVE-2022-25374 can potentially expose sensitive data captured in log files, leading to unauthorized access or disclosure of sensitive information.
How do I fix CVE-2022-25374?
CVE-2022-25374 has been fixed in version v202202-1 of HashiCorp Terraform Enterprise. It is recommended to update to this version to prevent the vulnerability.
Where can I find more information about CVE-2022-25374?
You can find more information about CVE-2022-25374 on the HashiCorp discussion forum at the following URL: https://discuss.hashicorp.com/t/hcsec-2022-06-terraform-enterprise-may-capture-sensitive-data-in-logs/