PT-2021-19406 · Hashicorp · Hashicorp Terraform Enterprise

Published

2021-03-26

·

Updated

2022-07-12

·

CVE-2021-3153

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Terraform Enterprise versions up to v202102-2
Description The issue concerns a failure to enforce an organization-level setting that requires users within an organization to have two-factor authentication enabled. This affects users in such organizations, potentially allowing access without the required two-factor authentication. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For HashiCorp Terraform Enterprise versions up to v202102-2, update to version v202103-1 or later to resolve the issue. As a temporary workaround, consider enforcing two-factor authentication through other means until the update can be applied. Restrict access to sensitive resources within the organization to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3153

Affected Products

Hashicorp Terraform Enterprise