CVE-2021-3153
CVE-2021-3153 is a medium-severity vulnerability in Hashicorp Terraform Enterprise with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 4.0
- EPSS exploit prediction: 1% (49th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Hashicorp Terraform Enterprise
- Published:
- Last modified:
Description
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
Frequently asked questions
- What is CVE-2021-3153?
- HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
- How severe is CVE-2021-3153?
- CVE-2021-3153 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2021-3153 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (49th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-3153?
- CVE-2021-3153 affects Hashicorp Terraform Enterprise. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-3153?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-3153 published?
- CVE-2021-3153 was published on 2021-03-26 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:hashicorp:terraform_enterprise:*:*:*:*:*:*:*:*
More vulnerabilities in Hashicorp Terraform Enterprise
- CVE-2021-40862 — High (CVSS 8.8): HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to…
- CVE-2022-25374 — High (CVSS 7.5): HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP…
- CVE-2020-15511 — Medium (CVSS 5.3): HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when…
- CVE-2023-3114 — Medium (CVSS 5.0): Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the…
All CVEs affecting Hashicorp Terraform Enterprise →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-20317 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-19977 — Critical (CVSS 10.0): A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function…
- CVE-2026-59500 — Critical (CVSS 10.0): CWE-287: Improper Authentication
- CVE-2024-27253 — Critical (CVSS 10.0): IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to…
- CVE-2026-56162 — Critical (CVSS 10.0): Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62825 — Critical (CVSS 10.0): Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-287 (Improper Authentication) vulnerabilities →