This security bulletin contains one low risk vulnerability.
Exploit availability: NoDescription
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions to the API endpoint and erroneous disclosure of a sensitive URL to authenticated parties. A remote user can bypass implemented security restrictions and escalate privileges within the application.
Install updates from vendor's website.Vulnerable software versions
Terraform Enterprise: 201804-1 - 202112-1
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?