Skip to main content

Vendor/product archive

hashicorp / terraform_provider CVEs

Beta · best-effort

2 CVEs tagged to hashicorp / terraform_provider1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-13357

Published Nov 21, 2025

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. I…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-30476

Published Apr 22, 2021

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1