CBL Mariner 2.0 Security Update: terraform (CVE-2021-36230)
Discription
The version of terraform installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2021-36230 advisory.
– HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner.
Fixed in v202107-1. (CVE-2021-36230)
Note that Nessus has not tested for this issue but has instead relied only on the application’s self-reported version number.Read More
References
https://nvd.nist.gov/vuln/detail/CVE-2021-36230http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36230CVSS2
- Access Vector
- Access Complexity
- Authentication
- Confidentiality Impact
- Integrity Impact
- Availability Impact
- Network
- Low
- Single
- Partial
- Partial
- Partial
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
- Attack Vector
- Attack Complexity
- Privileges Required
- User Interaction
- Scope
- Confidentiality Impact
- Integrity Impact
- Availability Impact
- Network
- Low
- Low
- None
- Unchanged
- High
- High
- High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to Main