CVE-2025-13432 — Incorrect Authorization in Terraform Enterprise
Severity
4.3MEDIUMNVD
EPSS
0.0%
top 91.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Description
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-3m8w-h8mm-xqvp: Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace↗2025-11-21