Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp terraform Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp terraform Enterprise |
Fri, 21 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Fri, 21 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3. | |
| Title | Terraform Enterprise state versions can be created by users with specific permissions without sufficient write access | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-11-21T15:13:18.518Z
Reserved: 2025-11-19T16:38:34.330Z
Link: CVE-2025-13432
Updated: 2025-11-21T15:13:07.453Z
Status : Awaiting Analysis
Published: 2025-11-21T15:15:51.660
Modified: 2025-11-25T22:16:42.557
Link: CVE-2025-13432
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:22Z