Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-29705.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-29705
Upstream
Published
2023-09-08T18:15:07Z
Modified
2026-04-21T04:26:03.790783Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2023-4782 affecting package terraform for versions less than 1.3.2-19
Details

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the init operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.

References

Affected packages

Azure Linux:2 / terraform

Package

Name
terraform
Purl
pkg:rpm/azure-linux/terraform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.2-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-29705.json"