CVE-2023-4782Path Traversal in Hashicorp Terraform

CWE-22Path Traversal6 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 84.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateJan 15

Description

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

3
OSV
Terraform allows arbitrary file write during the `init` operation in github.com/hashicorp/terraform2024-08-21
OSV
Terraform allows arbitrary file write during the `init` operation2023-09-08
GHSA
Terraform allows arbitrary file write during the `init` operation2023-09-08

📋Vendor Advisories

2
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Terraform) — CVE-2023-47822025-01-15
Microsoft
Terraform Allows Arbitrary File Write During Init Operation2023-09-12