Database/Control plane, storage & DevOps
Terraform Enterprise: Missing authorization on a subset of run-token API requests
CVSS 8.8CVE-2021-36230Control plane, storage & DevOpscurated
Impact
Missing authorization on a subset of run-token API requests -> privilege escalation to organization owner
Who can reach it
Network (remote)
What to do
Control-plane: upgrade TFE to v202107-1+; review org owner membership
References
Related entries
- AMD System Management Mode (SMM) interrupt handler: A flaw in the AMD SMM interrupt handler lets a high-privilegeCVE-2021-39298 · AMD System Management Mode (SMM) interrupt handlerHigh
- MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operationsCVE-2021-41137 · MinIO (IAM policy engine)High
- MinIO: Hand-crafted admin API call updates a user's policyCVE-2021-43858 · MinIOHigh
- Samba (SMB gateway): Out-of-bounds heap read/write in vfs_fruitCVE-2021-44142 · Samba (SMB gateway)High
- HTCondor (SciTokens authentication): A SciToken is granted more authorization than the token's scopes should permit.CVE-2021-45102 · HTCondor (SciTokens authentication)High
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateCVE-2022-1552 · PostgreSQLHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.