Description
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2517 | Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7. |
Github GHSA |
GHSA-h626-pv66-hhm7 | Terraform allows arbitrary file write during the `init` operation |
References
History
Thu, 26 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-09-26T14:05:36.006Z
Reserved: 2023-09-05T20:20:17.024Z
Link: CVE-2023-4782
Updated: 2024-08-02T07:38:00.485Z
Status : Modified
Published: 2023-09-08T18:15:07.707
Modified: 2024-11-21T08:35:58.410
Link: CVE-2023-4782
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA