HashiCorp Terraform Enterprise
cpe:2.3:a:hashicorp:terraform_enterprise:*:*:*:*:*:*:*
- <= 1.1.0
- <= 1.0.2
A vulnerability exists in Terraform Enterprise versions prior to 1.1.1 and 1.0.2, allowing users with limited permissions to create new Terraform state versions in a workspace. This could lead to unauthorized changes in infrastructure if the new state version is applied, either automatically or with approval from a user who has the necessary permissions. The issue arises from a combination of workspace and organizational permissions that, when held by a user, enable them to overwrite state versions without proper write access.
Exploitation of this vulnerability could result in unauthorized modifications to infrastructure managed by Terraform, potentially leading to disruptions or misconfigurations.
Users are advised to upgrade to Terraform Enterprise versions 1.1.1 or 1.0.3.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.