PT-2026-56005 · Hashicorp · Terraform Enterprise
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Terraform Enterprise versions prior to 2.0.4
Terraform Enterprise versions prior to 1.2.4
Description
An issue exists in the version control system (VCS) ingestion of registry modules where the intended boundary on packaged module content is not correctly enforced. This allows an authenticated user to include files from outside the intended repository content within a module and subsequently download them, which may expose sensitive files that are readable by the ingestion process.
Recommendations
Update to version 2.0.4.
Update to version 1.2.4.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Terraform Enterprise