Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cgg-f8v8-8rxw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

EPSS

Процентиль: 67%
0.00553
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

CVSS3: 8.8
msrc
почти 4 года назад

Описание отсутствует

EPSS

Процентиль: 67%
0.00553
Низкий

Дефекты

CWE-863