{"id":"GHSA-h626-pv66-hhm7","summary":"Terraform allows arbitrary file write during the `init` operation","details":"Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.","aliases":["CVE-2023-4782","GO-2023-2055"],"modified":"2024-08-21T14:57:30.607057Z","published":"2023-09-08T18:30:29Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-09-08T19:43:48Z","nvd_published_at":"2023-09-08T18:15:07Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4782"},{"type":"WEB","url":"https://github.com/hashicorp/terraform/pull/33745"},{"type":"WEB","url":"https://github.com/hashicorp/terraform/commit/0f2314fb62193c4be94328cc026fcb7ec1e9b893"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2023-27-terraform-allows-arbitrary-file-write-during-init-operation/58082"},{"type":"PACKAGE","url":"https://github.com/hashicorp/terraform"},{"type":"WEB","url":"https://github.com/hashicorp/terraform/releases/tag/v1.5.7"}],"affected":[{"package":{"name":"github.com/hashicorp/terraform","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/terraform"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.8"},{"fixed":"1.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-h626-pv66-hhm7/GHSA-h626-pv66-hhm7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N"}]}