<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hashicorp Terraform</title>
  <link>https://cvedaily.com/pages/tags/terraform.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/terraform.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hashicorp Terraform</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47358 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47358</guid>
    <pubDate>Tue, 19 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47358</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47357 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47357</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47357</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-g…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7428 – Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Clo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7428</guid>
    <pubDate>Tue, 12 May 2026 10:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7428</strong></p>
  <p>Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database.     Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35533 – mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35533</guid>
    <pubDate>Tue, 07 Apr 2026 21:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35533</strong></p>
  <p>mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27900 – The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive info...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27900</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27900</strong></p>
  <p>The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explicitly enabled (for example in local troubleshooting, CI/CD jobs, or centralized log collection). If e…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27640 – tfplan2md is software for converting Terraform plan JSON files into human-readab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27640</guid>
    <pubDate>Wed, 25 Feb 2026 04:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27640</strong></p>
  <p>tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sen…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25499 – Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25499</guid>
    <pubDate>Wed, 04 Feb 2026 21:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25499</strong></p>
  <p>Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68922 – OpenOps before 0.6.11 allows remote code execution in the Terraform block.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68922</guid>
    <pubDate>Thu, 25 Dec 2025 00:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68922</strong></p>
  <p>OpenOps before 0.6.11 allows remote code execution in the Terraform block.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66411 – Coder allows organizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66411</guid>
    <pubDate>Wed, 03 Dec 2025 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66411</strong></p>
  <p>Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13432 – Terraform state versions can be created by a user with specific but insufficient...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13432</guid>
    <pubDate>Fri, 21 Nov 2025 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13432</strong></p>
  <p>Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13357 – Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13357</guid>
    <pubDate>Fri, 21 Nov 2025 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13357</strong></p>
  <p>Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58445 – Atlantis is a self-hosted golang application that listens for Terraform pull req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58445</guid>
    <pubDate>Sat, 06 Sep 2025 20:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58445</strong></p>
  <p>Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. Th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58437 – Coder allows organizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58437</guid>
    <pubDate>Sat, 06 Sep 2025 03:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58437</strong></p>
  <p>Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0  and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a user when a workspace is started. It is automatically exposed via coder_workspace_owner.session_token. Prebuilt workspaces…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2180 – An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma®...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2180</guid>
    <pubDate>Wed, 13 Aug 2025 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2180</strong></p>
  <p>An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud.  This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-46735 – Terraform WinDNS Provider allows users to manage their Windows DNS server resour...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46735</guid>
    <pubDate>Tue, 06 May 2025 17:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-46735</strong></p>
  <p>Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the underlyding powershell command prompt. Version 1.0.5 contains a fix for the issue.</p>
  <p><strong>CVSS:</strong> 1.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56802 – Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56802</guid>
    <pubDate>Tue, 31 Dec 2024 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56802</strong></p>
  <p>Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry.  User must upgrade to 0.9.2.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-52009 – Atlantis is a self-hosted golang application that listens for Terraform pull req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52009</guid>
    <pubDate>Fri, 08 Nov 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-52009</strong></p>
  <p>Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administra…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47083 – Power Platform Terraform Provider allows managing environments and other resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47083</guid>
    <pubDate>Wed, 25 Sep 2024 22:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47083</strong></p>
  <p>Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs. This exposure occurs due to an error in the logging code that causes the `client_s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27918 – Coder allows oragnizations to provision remote development environments via Terr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27918</guid>
    <pubDate>Thu, 21 Mar 2024 02:52:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27918</strong></p>
  <p>Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in Coder's OIDC authentication could allow an attacker to bypass the `CODER_OIDC_EMAIL_DOMAIN` verification and create an account with an email not in the allowlist. Deployments are only affected if the OIDC provider allows users to create accounts on t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4782 – Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4782</guid>
    <pubDate>Fri, 08 Sep 2023 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4782</strong></p>
  <p>Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34236 – Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34236</guid>
    <pubDate>Fri, 14 Jul 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34236</strong></p>
  <p>Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from Weave GitOps Terraform Runners (`tf-runner`), where sensitive data is inadverte…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3114 – Terraform Enterprise since v202207-1 did not properly implement authorization ru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3114</guid>
    <pubDate>Thu, 22 Jun 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3114</strong></p>
  <p>Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool. This vulnerability, CVE-2023-3114, is fixed in Terraform…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-30618 – Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30618</guid>
    <pubDate>Fri, 21 Apr 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-30618</strong></p>
  <p>Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the `info` logging level during the `kitchen converge` action…</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39326 – kartverket/github-workflows are shared reusable workflows for GitHub Actions. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39326</guid>
    <pubDate>Tue, 25 Oct 2022 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39326</strong></p>
  <p>kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `run-terraform` reusable workflow from the kartverket/github-workflows repo are affected by a code injection vulnerability. A malicious actor could potentially send a PR with a malicious payload leading to execution of arbitrary JavaScript code in the context of the workflow. Use…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25374 – HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 we...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25374</guid>
    <pubDate>Fri, 25 Feb 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25374</strong></p>
  <p>HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40862 – HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40862</guid>
    <pubDate>Wed, 15 Sep 2021 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40862</strong></p>
  <p>HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36230 – HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36230</guid>
    <pubDate>Tue, 20 Jul 2021 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36230</strong></p>
  <p>HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3040 – An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3040</guid>
    <pubDate>Thu, 10 Jun 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3040</strong></p>
  <p>An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-30476 – HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30476</guid>
    <pubDate>Thu, 22 Apr 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-30476</strong></p>
  <p>HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3035 – An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3035</guid>
    <pubDate>Tue, 20 Apr 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3035</strong></p>
  <p>An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3153 – HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3153</guid>
    <pubDate>Fri, 26 Mar 2021 03:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3153</strong></p>
  <p>HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13359 – The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13359</guid>
    <pubDate>Thu, 19 Nov 2020 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13359</strong></p>
  <p>The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15511 – HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15511</guid>
    <pubDate>Thu, 30 Jul 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15511</strong></p>
  <p>HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19316 – When using the Azure backend with a shared access signature (SAS), Terraform ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19316</guid>
    <pubDate>Mon, 02 Dec 2019 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19316</strong></p>
  <p>When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-8944 – An Information Exposure issue in the Terraform deployment step in Octopus Deploy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8944</guid>
    <pubDate>Wed, 20 Feb 2019 03:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-8944</strong></p>
  <p>An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-9057 – aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9057</guid>
    <pubDate>Tue, 27 Mar 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-9057</strong></p>
  <p>aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-332</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9057">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
