Hashicorp

Terraform

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Published 08.09.2023 18:15:07
  • Last modified 21.11.2024 08:35:58

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.

  • EPSS 0.55%
  • Published 20.07.2021 21:15:07
  • Last modified 21.11.2024 06:13:21

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

  • EPSS 0.18%
  • Published 02.12.2019 21:15:16
  • Last modified 21.11.2024 04:34:33

When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.

  • EPSS 0.49%
  • Published 27.03.2018 18:29:00
  • Last modified 21.11.2024 04:14:53

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM...