boundaryGHSA-9vrm-v9xv-x3xr
HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
High7.1CVE-2023-0690 · Published Jul 6, 2023 · updated Aug 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/boundary Go | >= 0.10.0, < 0.12.0 | 0.12.0 |
Details and references
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This would result in the credentials being stored in plaintext on the Boundary PKI worker’s disk. This issue is fixed in version 0.12.0.
More boundary advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 52024 | Boundary vulnerable to session hijacking through TLS certificate tampering CVE-2024-1052High8.0fixed in 0.15.0 | High8.0 | 0.15.0 |
| Oct 272022 | Hashicorp Boundary vulnerable to clickjacking CVE-2022-36182Medium6.1no fix yet | Medium6.1 | No fix yet |
| Dec 132024 | Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service CVE-2024-12289Medium5.9fixed in 0.18.2 | Medium5.9 | 0.18.2 |
| May 5 | Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes CVE-2026-7776High7.5fixed in 0.19.5, 0.20.3, 0.21.3 | High7.5 | 0.19.5, 0.20.3, 0.21.3 |