Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36130


HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.


Published

2022-09-01T02:15:07.980

Last Modified

2024-11-21T07:12:27.663

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-345

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp boundary < 0.10.2 Yes

References