← Back to CVE List

CVE-2021-40862

Published: 2021-09-15T19:15Z
Last Modified: 2024-11-21T06:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt