Headline
GHSA-h626-pv66-hhm7: Terraform allows arbitrary file write during the `init` operation
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the init
operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
Terraform allows arbitrary file write during the `init` operation
Moderate severity GitHub Reviewed Published Sep 8, 2023 to the GitHub Advisory Database • Updated Sep 8, 2023
Related news
CVE-2023-4782: HCSEC-2023-27 - Terraform Allows Arbitrary File Write During Init Operation
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.