Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2020-15511

Disclosure Date: July 30, 2020 (last updated November 28, 2024)
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.
Attacker Value
Unknown

CVE-2019-19316

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.
Attacker Value
Unknown

CVE-2018-9057

Disclosure Date: March 27, 2018 (last updated November 26, 2024)
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
0