← Back

CVE-2025-13432

nvd nist
Published: Nov 21, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: security@hashicorp.com (Secondary)

Description

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

Affected (2)

Products: Hashicorp: Terraform
1 product
Terraform
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Hashicorp
From 1.0.0 to 1.0.3
Version 1.1.0

Timeline

No history available yet.