HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.
References
Configurations
History
21 Nov 2024, 07:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://discuss.hashicorp.com - Vendor Advisory | |
References | () https://discuss.hashicorp.com/t/hcsec-2022017-boundary-allowed-access-to-host-sets-and-credential-sources-for-authorized-users-of-another-scope/43493 - Vendor Advisory |
Information
Published : 2022-09-01 02:15
Updated : 2024-11-21 07:12
NVD link : CVE-2022-36130
Mitre link : CVE-2022-36130
CVE.ORG link : CVE-2022-36130
JSON object : View
Products Affected
hashicorp
- boundary
CWE
CWE-345
Insufficient Verification of Data Authenticity