Vulnerability Details CVE-2022-25374
HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-25374
-
cpe:2.3:a:hashicorp:terraform_enterprise:-
-
cpe:2.3:a:hashicorp:terraform_enterprise:202007-1
-
cpe:2.3:a:hashicorp:terraform_enterprise:202106-1
-
cpe:2.3:a:hashicorp:terraform_enterprise:202107-1
-
cpe:2.3:a:hashicorp:terraform_enterprise:202108-1
-
cpe:2.3:a:hashicorp:terraform_enterprise:202109-1