End of life: 5/14/2025, Latest version: 1.10.5
End of life: 5/14/2025, Latest version: 1.10.5
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the init operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
End of life: 2/27/2025, Latest version: 1.9.8
End of life: 2/27/2025, Latest version: 1.9.8
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
End of life: 11/26/2024, Latest version: 1.8.5
End of life: 11/26/2024, Latest version: 1.8.5
End of life: 6/26/2024, Latest version: 1.7.5
End of life: 6/26/2024, Latest version: 1.7.5
End of life: 4/10/2024, Latest version: 1.6.6
End of life: 4/10/2024, Latest version: 1.6.6
End of life: 1/17/2024, Latest version: 1.5.7
End of life: 1/17/2024, Latest version: 1.5.7
End of life: 10/4/2023, Latest version: 1.4.7
End of life: 10/4/2023, Latest version: 1.4.7
End of life: 6/12/2023, Latest version: 1.3.10
End of life: 6/12/2023, Latest version: 1.3.10
End of life: 3/8/2023, Latest version: 1.2.9
End of life: 3/8/2023, Latest version: 1.2.9
End of life: 9/21/2022, Latest version: 1.1.9
End of life: 9/21/2022, Latest version: 1.1.9
End of life: 5/18/2022, Latest version: 1.0.11
End of life: 5/18/2022, Latest version: 1.0.11