HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 07:12
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://discuss.hashicorp.com - Vendor Advisory | |
| References | () https://discuss.hashicorp.com/t/hcsec-2022017-boundary-allowed-access-to-host-sets-and-credential-sources-for-authorized-users-of-another-scope/43493 - Vendor Advisory | 
09 Sep 2022, 14:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://discuss.hashicorp.com - Vendor Advisory | |
| References | (MISC) https://discuss.hashicorp.com/t/hcsec-2022017-boundary-allowed-access-to-host-sets-and-credential-sources-for-authorized-users-of-another-scope/43493 - Vendor Advisory | |
| CWE | CWE-345 | |
| CPE | cpe:2.3:a:hashicorp:boundary:*:*:*:*:*:*:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.9 | 
01 Sep 2022, 07:00
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-09-01 02:15
Updated : 2024-11-21 07:12
NVD link : CVE-2022-36130
Mitre link : CVE-2022-36130
CVE.ORG link : CVE-2022-36130
JSON object : View
Products Affected
                hashicorp
- boundary
CWE
                
                    
                        
                        CWE-345
                        
            Insufficient Verification of Data Authenticity
