GHSA-xx83-cxmq-x89m

Suggest an improvement
Source
https://github.com/advisories/GHSA-xx83-cxmq-x89m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-xx83-cxmq-x89m/GHSA-xx83-cxmq-x89m.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-xx83-cxmq-x89m
Aliases
Published
2024-12-13T00:30:50Z
Modified
2024-12-18T17:12:03.369898Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
Details

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process.

This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

Database specific
{
    "nvd_published_at": "2024-12-12T23:15:10Z",
    "github_reviewed": true,
    "github_reviewed_at": "2024-12-13T20:37:17Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-460"
    ]
}
References

Affected packages

Go / github.com/hashicorp/boundary

Package

Name
github.com/hashicorp/boundary
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/boundary

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.18.2