Vulnerabilities > Hashicorp > Boundary > 0.8.1

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-1052 Improper Certificate Validation vulnerability in Hashicorp Boundary
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering.
network
high complexity
hashicorp CWE-295
8.0
2022-10-27 CVE-2022-36182 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hashicorp Boundary
Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
network
low complexity
hashicorp CWE-1021
6.1
2022-09-01 CVE-2022-36130 Insufficient Verification of Data Authenticity vulnerability in Hashicorp Boundary
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope.
network
low complexity
hashicorp CWE-345
critical
9.9