BoundaryGHSA-vh73-q3rw-qx7w
Boundary vulnerable to session hijacking through TLS certificate tampering
High8.0CVE-2024-1052 · Published Feb 5, 2024 · updated Jun 28, 2024
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/boundary Go | >= 0.8.0, < 0.15.0 | 0.15.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-295
- Also known as
- CVE-2024-1052, GO-2024-2532
More Boundary advisories
All Boundary| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 5 | Boundary: denial of service | High7.5 | 0.19.5+2 more |
| Dec 132024 | Boundary Community Edition and Boundary Enterprise | Medium5.9 | 0.18.2 |
| Jul 62023 | HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured | High7.1 | 0.12.0 |
| Oct 272022 | Hashicorp Boundary vulnerable to clickjacking | Medium6.1 | No fix yet |