Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Terraform Enterprise state versions can be created by users with specific permissions without sufficient write access
Vulnerability Description
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
HashiCorp Terraform Enterprise 安全漏洞
Vulnerability Description
HashiCorp Terraform Enterprise是美国HashiCorp公司的一个开发工具。 HashiCorp Terraform Enterprise存在安全漏洞,该漏洞源于权限不足,可能导致基础设施变更。
CVSS Information
N/A
Vulnerability Type
N/A