CVE-2024-56802: Pacovk Tapir
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.
Affected products
- Pacovk Tapir: from 0.9.0, before 0.9.2 (fixed in 0.9.2)
Published 2024-12-31. Last modified 2026-06-17.