PT-2023-16458 · Hashicorp · Hashicorp Boundary
CVE-2023-0690
·
Publicado
2023-02-08
·
Atualizado
2024-08-20
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Boundary versions 0.10.0 through 0.11.2
Description
The issue arises when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file. After an automatic rotation, new credentials may not be encrypted via the intended KMS, resulting in them being stored in plaintext on the Boundary PKI worker’s disk.
Recommendations
For HashiCorp Boundary versions 0.10.0 through 0.11.2, update to version 0.12.0 to resolve the issue. As a temporary workaround, consider restricting access to the credentials stored on the Boundary PKI worker’s disk to minimize the risk of exploitation.
Exploit
Correção
Cleartext Storage of Sensitive Information
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hashicorp Boundary