BoundaryGHSA-xqv2-3vvq-qg6r
Hashicorp Boundary vulnerable to clickjacking
Medium6.1CVE-2022-36182 · Published Oct 27, 2022 · updated Nov 8, 2023
Hashicorp Boundary is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/boundary Go | <= 0.11.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1021
- Also known as
- CVE-2022-36182
More Boundary advisories
All Boundary| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 5 | Boundary: denial of service | High7.5 | 0.19.5+2 more |
| Dec 132024 | Boundary Community Edition and Boundary Enterprise | Medium5.9 | 0.18.2 |
| Feb 52024 | Boundary vulnerable to session hijacking through TLS certificate tampering | High8.0 | 0.15.0 |
| Jul 62023 | HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured | High7.1 | 0.12.0 |