This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3526 | Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2. |
Github GHSA |
GHSA-xx83-cxmq-x89m | Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 29 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp boundary |
|
| Weaknesses | CWE-665 | |
| CPEs | cpe:2.3:a:hashicorp:boundary:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hashicorp
Hashicorp boundary |
Fri, 13 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Dec 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2. | |
| Title | Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service | |
| Weaknesses | CWE-460 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-12-13T19:35:10.676Z
Reserved: 2024-12-05T22:09:25.315Z
Link: CVE-2024-12289
Updated: 2024-12-13T19:32:46.633Z
Status : Analyzed
Published: 2024-12-12T23:15:10.500
Modified: 2025-12-29T17:17:19.510
Link: CVE-2024-12289
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA