Vulnerabilities > Hashicorp > Terraform Enterprise > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2021-3153 Improper Authentication vulnerability in Hashicorp Terraform Enterprise 2020071
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled.
network
low complexity
hashicorp CWE-287
6.5
2020-07-30 CVE-2020-15511 Unspecified vulnerability in Hashicorp Terraform Enterprise
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement.
network
low complexity
hashicorp
5.3