First published: Fri Sep 08 2023(Updated: )
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
Credit: security@hashicorp.com security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/hashicorp/terraform | >=1.0.8<1.5.7 | 1.5.7 |
Hashicorp Terraform | >=1.0.8<1.5.7 | |
HashiCorp Terraform | >=1.0.8<1.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4782 is a vulnerability in Terraform version 1.0.8 through 1.5.6 that allows arbitrary file write during the `init` operation.
CVE-2023-4782 can be exploited by running a maliciously crafted Terraform configuration during the `init` operation.
CVE-2023-4782 has a severity value of 7.8 (High).
You can fix CVE-2023-4782 by updating your Terraform version to 1.5.7 or later.
You can find more information about CVE-2023-4782 on the HashiCorp discussion forum, the NVD website, and the GitHub repository for Terraform.