CVE-2023-3114
CVSS V2 None
CVSS V3 None
Description
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool. This vulnerability, CVE-2023-3114, is fixed in Terraform Enterprise v202306-1.
Overview
- CVE ID
- CVE-2023-3114
- Assigner
- HashiCorp
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-06-22T21:59:46.778Z
- Last Modified Date
- 2023-06-22T21:59:46.778Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-3114 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3114 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 21:12:55 | Added to TrackCVE |