Skip to main content

Vendor/product archive

hashicorp / terraform CVEs

Beta · best-effort

5 CVEs tagged to hashicorp / terraform1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-13432

Published Nov 21, 2025

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructu…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4782

Published Sep 8, 2023

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36230

Published Jul 20, 2021

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19316

Published Dec 2, 2019

When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9057

Published Mar 27, 2018

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which mak…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1