Skip to content
BoundaryGHSA-xqv2-3vvq-qg6r

Hashicorp Boundary vulnerable to clickjacking

Medium6.1CVE-2022-36182 · Published Oct 27, 2022 · updated Nov 8, 2023

Hashicorp Boundary is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/boundary
Go
<= 0.11.0No fix yet
Details and references

More Boundary advisories

All Boundary
Advisory
Boundary: denial of service
High7.5May 5
Boundary Community Edition and Boundary Enterprise
Medium5.9Dec 13, 2024
Boundary vulnerable to session hijacking through TLS certificate tampering
High8.0Feb 5, 2024
HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
High7.1Jul 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.