Hashicorp
Hashicorp Terraform: vulnerabilidades y CVE
Hashicorp Terraform tiene 8 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45099 | Media (6.9) | 0.54% | — | 21 ago 2026 | Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's… |
| CVE-2026-71494 | Media (5.9) | 0.50% | — | 21 ago 2026 | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request… |
| CVE-2026-7428 | Crítica (9.2) | 0.41% | — | 12 may 2026 | Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote… |
| CVE-2025-13432 | Media (4.3) | 0.18% | — | 21 nov 2025 | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is… |
| CVE-2023-4782 | Alta (7.8) | 0.27% | — | 8 sept 2023 | Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7. |
| CVE-2021-36230 | Alta (8.8) | 0.95% | — | 20 jul 2021 | HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed… |
| CVE-2019-19316 | Alta (7.5) | 1.00% | — | 2 dic 2019 | When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. |
| CVE-2018-9057 | Crítica (9.8) | 1.9% | — | 27 mar 2018 | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to… |