Skip to content
BoundaryGHSA-vh73-q3rw-qx7w

Boundary vulnerable to session hijacking through TLS certificate tampering

High8.0CVE-2024-1052 · Published Feb 5, 2024 · updated Jun 28, 2024

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/boundary
Go
>= 0.8.0, < 0.15.00.15.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-295
Also known as
CVE-2024-1052, GO-2024-2532

More Boundary advisories

All Boundary
Advisory
Boundary: denial of service
High7.5May 5
Boundary Community Edition and Boundary Enterprise
Medium5.9Dec 13, 2024
HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
High7.1Jul 6, 2023
Hashicorp Boundary vulnerable to clickjacking
Medium6.1Oct 27, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.