Vulnerabilities (CVE)

Filtered by vendor Hashicorp Subscribe
Filtered by product Terraform Enterprise
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40862 1 Hashicorp 1 Terraform Enterprise 2022-07-12 6.5 MEDIUM 8.8 HIGH
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.