Skip to main content

Vendor/product archive

hashicorp / boundary CVEs

Beta · best-effort

5 CVEs tagged to hashicorp / boundary1 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-12289

Published Dec 12, 2024

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1052

Published Feb 5, 2024

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sess…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0690

Published Feb 8, 2023

HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new crede…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36182

Published Oct 27, 2022

Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perfor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36130

Published Sep 1, 2022

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escala…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1