Vulnerability Description
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Terraform Provider | < 2.19.1 |
References
- https://discuss.hashicorp.com/t/hcsec-2021-11-terraform-s-vault-provider-did-notVendor Advisory
- https://github.com/hashicorp/terraform-provider-vault/issues/996ExploitPatchThird Party Advisory
- https://discuss.hashicorp.com/t/hcsec-2021-11-terraform-s-vault-provider-did-notVendor Advisory
- https://github.com/hashicorp/terraform-provider-vault/issues/996ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-30476?
CVE-2021-30476 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
How severe is CVE-2021-30476?
CVE-2021-30476 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-30476?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Terraform Provider.