CVE-2023-3114

CVSS V2 None CVSS V3 None
Description
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool. This vulnerability, CVE-2023-3114, is fixed in Terraform Enterprise v202306-1.
Overview
  • CVE ID
  • CVE-2023-3114
  • Assigner
  • HashiCorp
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-06-22T21:59:46.778Z
  • Last Modified Date
  • 2023-06-22T21:59:46.778Z
History
Created Old Value New Value Data Type Notes
2024-06-24 21:12:55 Added to TrackCVE