Vulnerabilities (CVE)

Filtered by vendor Hashicorp Subscribe
Filtered by product Terraform Enterprise
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3153 1 Hashicorp 1 Terraform Enterprise 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
CVE-2020-15511 1 Hashicorp 1 Terraform Enterprise 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.