Skip to content
boundaryGHSA-9vrm-v9xv-x3xr

HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured

High7.1CVE-2023-0690 · Published Jul 6, 2023 · updated Aug 20, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/boundary
Go
>= 0.10.0, < 0.12.00.12.0
Details and references

HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This would result in the credentials being stored in plaintext on the Boundary PKI worker’s disk. This issue is fixed in version 0.12.0.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-311, CWE-312
Also known as
CVE-2023-0690, GO-2023-1898

More boundary advisories

All
DateAdvisory
Feb 52024Boundary vulnerable to session hijacking through TLS certificate tampering
CVE-2024-1052High8.0fixed in 0.15.0
Oct 272022Hashicorp Boundary vulnerable to clickjacking
CVE-2022-36182Medium6.1no fix yet
Dec 132024Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
CVE-2024-12289Medium5.9fixed in 0.18.2
May 5Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVE-2026-7776High7.5fixed in 0.19.5, 0.20.3, 0.21.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.