Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-13432


Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.


Published

2025-11-21T15:15:51.660

Last Modified

2025-12-10T21:02:36.733

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp terraform < 1.0.3 Yes
Application hashicorp terraform 1.1.0 Yes

References