Impact
HashiCorp Terraform Enterprise contains a path‑traversal flaw in its version control system ingestion of registry modules, allowing an authenticated user to reference files outside the intended repository and download them, which can expose sensitive files read by the ingestion process.
Affected Systems
All instances of Terraform Enterprise whose installed versions are earlier than v2.0.4 or v1.2.4 are affected, as those releases contain the vulnerability.
Risk and Exploitability
The vulnerability has a CVSS score of 7.7 and an EPSS score of less than 1 %, and it is not listed in the CISA KEV catalog. Although an attacker must first authenticate, any privileged user can exploit the flaw to read arbitrary files, which represents a moderate to high risk of data exposure.
OpenCVE Enrichment