Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.
References
Configurations
History
No history.
Information
Published : 2024-02-05 21:15
Updated : 2024-02-15 18:49
NVD link : CVE-2024-1052
Mitre link : CVE-2024-1052
CVE.ORG link : CVE-2024-1052
JSON object : View
Products Affected
hashicorp
- boundary
CWE
CWE-295
Improper Certificate Validation