Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvhx-v7vc-cm6c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.

HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.

EPSS

Процентиль: 66%
0.00512
Низкий

8.8 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.

EPSS

Процентиль: 66%
0.00512
Низкий

8.8 High

CVSS3

Дефекты

CWE-668