VDB
CVE-2024-12289
CVE-2024-12289
PUBLISHED
CVSS 5.900000095367432 MEDIUM
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.
EPSS 0.39% · 31.1th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.39%
31.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | hashicorp/boundary | 0, 0 |
| hashicorp | boundary | 0.8.0, 0.17.0, 0.18.0 |
| HashiCorp | Boundary Enterprise | 0.8.0, 0.8.0 |
| HashiCorp | Boundary | 0.8.0, 0.8.0 |
Timeline
- Dec 12, 2024 CVE Published
- Dec 12, 2024 PoC Published
- Dec 13, 2024 EPSS Score
- Dec 13, 2024 PoC Published
- Dec 30, 2024 EPSS Score
- Jan 16, 2025 EPSS Score
- Feb 2, 2025 EPSS Score
- Feb 19, 2025 EPSS Score
- Mar 8, 2025 EPSS Score
- Mar 25, 2025 EPSS Score
- Apr 11, 2025 EPSS Score
- Apr 28, 2025 EPSS Score