CVE-2024-12289 MEDIUM

CVE-2024-12289: Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service

Vendor Hashicorp
Product Boundary
Weakness CWE-460
Published December 12, 2024
Last update December 13, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

Key dates

02Disclosure timeline

December 12, 2024 CVE published
December 13, 2024 Record updated