CVE-2023-3114: Hashicorp Terraform Enterprise
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that targeted an agent pool. This vulnerability, CVE-2023-3114, is fixed in Terraform Enterprise v202306-1.
Affected products
- Hashicorp Terraform Enterprise: from 202207-1, before 202306-1 (fixed in 202306-1)
Published 2023-06-22. Last modified 2026-06-17.