PT-2024-17529 · Hashicorp · Boundary Enterprise+1

Published

2024-12-12

·

Updated

2025-12-29

·

CVE-2024-12289

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Boundary Community Edition versions prior to 0.16.4 Boundary Community Edition versions prior to 0.17.3 Boundary Community Edition versions prior to 0.18.2 Boundary Enterprise versions prior to 0.16.4 Boundary Enterprise versions prior to 0.17.3 Boundary Enterprise versions prior to 0.18.2
Description The issue arises from incorrect handling of HTTP requests during the initialization of the Boundary controller. This can cause the Boundary server to terminate prematurely. The vulnerability is only present during the initialization phase, which typically lasts a few milliseconds during the startup process.
Recommendations For Boundary Community Edition versions prior to 0.16.4, update to version 0.16.4 or later. For Boundary Community Edition versions prior to 0.17.3, update to version 0.17.3 or later. For Boundary Community Edition versions prior to 0.18.2, update to version 0.18.2 or later. For Boundary Enterprise versions prior to 0.16.4, update to version 0.16.4 or later. For Boundary Enterprise versions prior to 0.17.3, update to version 0.17.3 or later. For Boundary Enterprise versions prior to 0.18.2, update to version 0.18.2 or later.

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12289
GHSA-XX83-CXMQ-X89M
GO-2024-3335
OPENSUSE-SU-2024:14603-1

Affected Products

Boundary Community Edition
Boundary Enterprise