VYPR
Medium severity4.3NVD Advisory· Published Nov 21, 2025· Updated Jun 17, 2026

CVE-2025-13432

CVE-2025-13432

Description

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Hashicorp/Terraform Enterprisellm-fuzzy2 versions
    before 1.1.1 and 1.0.3+ 1 more
    • (no CPE)range: before 1.1.1 and 1.0.3
    • (no CPE)range: 1.0.0
  • cpe:2.3:a:hashicorp:terraform:*:*:*:*:enterprise:*:*:*+ 1 more
    • cpe:2.3:a:hashicorp:terraform:*:*:*:*:enterprise:*:*:*range: >=1.0.0,<1.0.3
    • cpe:2.3:a:hashicorp:terraform:1.1.0:*:*:*:enterprise:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.