CVE-2023-3114: Terraform Enterprise Agent Pool Controls Allowed Unauthorized Workspaces To Target an Agent Pool
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool. This vulnerability, CVE-2023-3114, is fixed in Terraform Enterprise v202306-1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Terraform Enterpriseto a version that resolves this vulnerability.Fixed in v202306-1Patch CVE-2023-3114
Event History
Frequently Asked Questions
What is CVE-2023-3114?
CVE-2023-3114 is a vulnerability in Terraform Enterprise that allows unauthorized agents to target a workspace.
How does CVE-2023-3114 affect Terraform Enterprise?
CVE-2023-3114 affects Terraform Enterprise by not properly implementing authorization rules for agent pools.
What is the severity of CVE-2023-3114?
CVE-2023-3114 has a severity rating of high (7.7).
How can the CVE-2023-3114 vulnerability be fixed?
To fix the CVE-2023-3114 vulnerability, update Terraform Enterprise to a version that properly implements authorization rules for agent pools.
Where can I find more information about CVE-2023-3114?
More information about CVE-2023-3114 can be found at this link: [https://discuss.hashicorp.com/t/hcsec-2023-18-terraform-enterprise-agent-pool-controls-allowed-unauthorized-workspaces-to-target-an-agent-pool/55329]