Improper Authorization in Terraform Enterprise - CVE-2023-3114
Published: August 28, 2023
Terraform Enterprise
HashiCorp
Description
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to improper implementation of authorization rules for agent pools. A remote user can target any workspace within the organization or access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool.