Vulnerability Description
Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Boundary | < 0.11.0 |
Related Weaknesses (CWE)
References
- https://owasp.org/www-community/attacks/ClickjackingThird Party Advisory
- https://packetstormsecurity.com/files/168654/Hashicorp-Boundary-Clickjacking.htmThird Party AdvisoryVDB Entry
- https://owasp.org/www-community/attacks/ClickjackingThird Party Advisory
- https://packetstormsecurity.com/files/168654/Hashicorp-Boundary-Clickjacking.htmThird Party AdvisoryVDB Entry
FAQ
What is CVE-2022-36182?
CVE-2022-36182 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions o...
How severe is CVE-2022-36182?
CVE-2022-36182 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36182?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Boundary.