A remote authenticated attacker can exploit a vulnerability in HashiCorp Terraform Enterprise to disclose sensitive information, with a CVSS base score of 7.7 (High). Affected versions are HashiCorp Terraform Enterprise prior to version 2.0.4 and prior to version 1.2.4. A mitigation is available, though the article does not specify a fixed version number.
[WID-SEC-2026-2213] Hashicorp Terraform: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 7.7 (hoch) CVSS Temporal Score 6.7 (mittel) Remoteangriff ja Datum 06.07.2026 Stand 07.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Terraform ist ein Infrastruktur-als-Code-Tool. Produkte 06.07.2026 Hashicorp Terraform Enterprise <2.0.4 Hashicorp Terraform Enterprise <1.2.4 Angriff Angriff Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Hashicorp Terraform ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben