TLS Certificate Tampering Vulnerability in Boundary Enterprise
CVE-2024-1052
8HIGH
Key Information:
- Vendor
Hashicorp
- Vendor
- CVE Published:
- 5 February 2024
What is CVE-2024-1052?
Boundary and Boundary Enterprise by HashiCorp are susceptible to session hijacking due to vulnerabilities associated with TLS certificate tampering. An attacker with the capability to enumerate active or pending sessions may obtain a private key linked to a session and a valid trust on first use (TOFU) token. Leveraging this information, the attacker can craft a malicious TLS certificate to hijack an active session, leading to unauthorized access to the underlying services or applications. This vulnerability poses a significant risk to users and necessitates immediate attention.
Affected Version(s)
Boundary Enterprise Windows 0.8.0 < 0.15.0
Boundary Windows 0.8.0 < 0.15.0