PT-2021-19406 · Hashicorp · Hashicorp Terraform Enterprise
Published
2021-03-26
·
Updated
2022-07-12
·
CVE-2021-3153
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Terraform Enterprise versions up to v202102-2
Description
The issue concerns a failure to enforce an organization-level setting that requires users within an organization to have two-factor authentication enabled. This affects users in such organizations, potentially allowing access without the required two-factor authentication. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations
For HashiCorp Terraform Enterprise versions up to v202102-2, update to version v202103-1 or later to resolve the issue. As a temporary workaround, consider enforcing two-factor authentication through other means until the update can be applied. Restrict access to sensitive resources within the organization to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hashicorp Terraform Enterprise