PT-2022-23248 · Hashicorp · Hashicorp Boundary

Published

2022-10-27

·

Updated

2025-05-07

·

CVE-2022-36182

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hashicorp Boundary version 0.8.0
Description The issue allows for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site due to Clickjacking.
Recommendations For Hashicorp Boundary version 0.8.0, consider implementing frame busting techniques or other Clickjacking mitigation measures to prevent malicious actions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-36182
GHSA-XQV2-3VVQ-QG6R

Affected Products

Hashicorp Boundary