VYPR

Terraform Provider

by Hashicorp

CVEs (2)

  • CVE-2021-30476CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.02

    HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

  • CVE-2025-13357HigNov 21, 2025
    risk 0.41cvss 7.4epss 0.01

    Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in…