Description
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22850 | HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:54:50.714Z
Reserved: 2021-07-08T00:00:00.000Z
Link: CVE-2021-36230
No data.
Status : Modified
Published: 2021-07-20T21:15:07.700
Modified: 2024-11-21T06:13:21.177
Link: CVE-2021-36230
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD