PT-2023-16458 · Hashicorp · Hashicorp Boundary

CVE-2023-0690

·

Publicado

2023-02-08

·

Atualizado

2024-08-20

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Boundary versions 0.10.0 through 0.11.2
Description The issue arises when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file. After an automatic rotation, new credentials may not be encrypted via the intended KMS, resulting in them being stored in plaintext on the Boundary PKI worker’s disk.
Recommendations For HashiCorp Boundary versions 0.10.0 through 0.11.2, update to version 0.12.0 to resolve the issue. As a temporary workaround, consider restricting access to the credentials stored on the Boundary PKI worker’s disk to minimize the risk of exploitation.

Exploit

Correção

Cleartext Storage of Sensitive Information

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0690
GHSA-9VRM-V9XV-X3XR
GO-2023-1898

Produtos afetados

Hashicorp Boundary