Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh73-q3rw-qx7w

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Boundary vulnerable to session hijacking through TLS certificate tampering

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.

Пакеты

Наименование

github.com/hashicorp/boundary

go
Затронутые версииВерсия исправления

>= 0.8.0, < 0.15.0

0.15.0

EPSS

Процентиль: 53%
0.00303
Низкий

8 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8
nvd
около 2 лет назад

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.

EPSS

Процентиль: 53%
0.00303
Низкий

8 High

CVSS3

Дефекты

CWE-295