Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process.
This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Dec 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Dec 2024 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2. | |
Title | Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service | |
Weaknesses | CWE-460 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-12-13T19:35:10.676Z
Reserved: 2024-12-05T22:09:25.315Z
Link: CVE-2024-12289

Updated: 2024-12-13T19:32:46.633Z

Status : Received
Published: 2024-12-12T23:15:10.500
Modified: 2024-12-12T23:15:10.500
Link: CVE-2024-12289

No data.