PT-2021-18747 · Hashicorp · Hashicorp Terraform'S Vault Provider

Published

2021-04-22

·

Updated

2021-04-29

·

CVE-2021-30476

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Terraform’s Vault Provider versions prior to 2.19.1
Description The issue concerns the incorrect configuration of GCE-type bound labels for Vault’s GCP auth method in HashiCorp Terraform’s Vault Provider.
Recommendations For versions prior to 2.19.1, update to version 2.19.1 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-30476

Affected Products

Hashicorp Terraform'S Vault Provider