terraformGHSA-h626-pv66-hhm7
Terraform allows arbitrary file write during the `init` operation
Medium6.3CVE-2023-4782 · Published Sep 8, 2023 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/terraform Go | >= 1.0.8, < 1.5.7 | 1.5.7 |
Details and references
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2023-4782, GO-2023-2055
- nvd.nist.gov/vuln/detail/CVE-2023-4782
- github.com/hashicorp/terraform/pull/33745
- github.com/hashicorp/terraform/commit/0f2314fb62193c4be94328cc026fcb7ec1e9b893
- discuss.hashicorp.com/t/hcsec-2023-27-terraform-allows-arbitrary-file-write-during-init-operation/58082
- github.com/hashicorp/terraform
- github.com/hashicorp/terraform/releases/tag/v1.5.7
More terraform advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 182021 | Use of a Broken or Risky Cryptographic Algorithm in Terraform CVE-2019-19316High7.5fixed in 0.12.17 | High7.5 | 0.12.17 |