HashiCorp Boundary up to 0.10.1 did not properly perform...
Critical severity
Unreviewed
Published
Sep 2, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Sep 1, 2022
Published to the GitHub Advisory Database
Sep 2, 2022
Last updated
Jan 30, 2023
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.
References