VendorsHashiCorpboundaryany version
Vulnerabilities

HashiCorp Boundary any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-36130
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.
Published 2022-09-01 · Modified
9.9EPSS 0.005
CVE-2024-1052
Boundary Vulnerable to Session Hijacking Through TLS Certificate Tampering
Published 2024-02-05 · Modified
8.0EPSS 0.003
CVE-2023-0690
Boundary Workers Store Rotated Credentials in Plaintext Even When a Key Management Service Configured
Published 2023-02-08 · Modified
7.1EPSS 0.004
CVE-2022-36182
Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
Published 2022-10-27 · Modified
6.1EPSS 0.006
CVE-2024-12289
Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
Published 2024-12-12 · Analyzed
5.9EPSS 0.004