terraform-tfstate-exposure: Terraform State - File Exposure
2026-10-08PoC Public
Description
A Terraform state file was found exposed on the web server. State files map real world infrastructure to configuration and frequently store resource attributes such as passwords, private keys, database connection strings and access tokens in clear text, so public exposure can leak sensitive credentials for the managed infrastructure.
PoC
id: terraform-tfstate-exposure
info:
name: Terraform State - File Exposure
author: ChrisJr404
severity: high
description: |
A Terraform state file was found exposed on the web server. State files map real world infrastructure to configuration and frequently store resource attributes such as passwords, private keys, database connection strings and access tokens in clear text, so public exposure can leak sensitive credentials for the managed infrastructure.
reference:
- https://developer.hashicorp.com/terraform/language/state
- https://developer.hashicorp.com/terraform/language/state/sensitive-data
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cwe-id: CWE-538
metadata:
max-request: 2
google-query: intitle:"index of" "terraform.tfstate"
tags: exposure,config,terraform,iac,files
http:
- method: GET
path:
- "{{BaseURL}}/terraform.tfstate"
- "{{BaseURL}}/terraform.tfstate.backup"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"outputs"'
- '"version"'
- '"resources"'
condition: and
- type: word
part: header
words:
- "text/html"
negative: true
- type: status
status:
- 200
extractors:
- type: regex
part: body
group: 1
regex:
- '"terraform_version"\s*:\s*"([0-9.]+)"'
# digest: 4a0a004730450221009511dc6c44714502fd142fda5a3636e7711e17c58f5326c16060e1080aea7169022034dc42b08bc2f0f581ad87239a5e78121871695f56e1d0444319991eab376349:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.