CVE-2023-4782 MEDIUM

CVE-2023-4782: Terraform Allows Arbitrary File Write During Init Operation

Vendor Hashicorp
Product Terraform
Weakness CWE-22 · Path traversal
Published September 8, 2023
Last update September 26, 2024

CVSS base score

6.3/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N

What the vulnerability does

01Description

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.

Key dates

02Disclosure timeline

September 8, 2023 CVE published
September 26, 2024 Record updated