Lucene search

K

Terraform Provider Security Vulnerabilities

cve
cve

CVE-2021-30476

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in...

9.8CVSS

9.4AI Score

0.004EPSS

2021-04-22 05:15 PM
17
cve
cve

CVE-2018-9057

aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak...

9.8CVSS

9.2AI Score

0.004EPSS

2018-03-27 06:29 PM
32