Vulnerability Description
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Terraform Enterprise | <= 202102-2 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2021-06-terraform-enterprise-organization-Vendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2021-06-terraform-enterprise-organization-Vendor Advisory
FAQ
What is CVE-2021-3153?
CVE-2021-3153 is a vulnerability with a CVSS score of 6.5 (MEDIUM). HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
How severe is CVE-2021-3153?
CVE-2021-3153 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3153?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Terraform Enterprise.