Vulnerability Description
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Terraform Enterprise | <= 202108-1 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2021-25-terraform-enterprise-configurationVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2021-25-terraform-enterprise-configurationVendor Advisory
FAQ
What is CVE-2021-40862?
CVE-2021-40862 is a vulnerability with a CVSS score of 8.8 (HIGH). HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthoriz...
How severe is CVE-2021-40862?
CVE-2021-40862 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40862?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Terraform Enterprise.