#VU65308 Improper access control in Terraform Enterprise - CVE-2021-40862
Published: July 14, 2022
Terraform Enterprise
HashiCorp
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions to the API endpoint and erroneous disclosure of a sensitive URL to authenticated parties. A remote user can bypass implemented security restrictions and escalate privileges within the application.