Openbao

Openbao

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 14.05.2026 14:36:14
  • Zuletzt bearbeitet 14.05.2026 17:18:18

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outs...

  • EPSS 0.05%
  • Veröffentlicht 21.04.2026 00:47:38
  • Zuletzt bearbeitet 24.04.2026 13:29:24

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.04.2026 00:44:53
  • Zuletzt bearbeitet 01.05.2026 16:36:07

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy`...

  • EPSS 0.02%
  • Veröffentlicht 21.04.2026 00:43:22
  • Zuletzt bearbeitet 24.04.2026 13:27:34

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's pre...

  • EPSS 0.03%
  • Veröffentlicht 21.04.2026 00:19:39
  • Zuletzt bearbeitet 24.04.2026 13:28:39

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by...

  • EPSS 0.05%
  • Veröffentlicht 27.03.2026 14:12:33
  • Zuletzt bearbeitet 30.03.2026 17:21:54

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `er...

  • EPSS 0.04%
  • Veröffentlicht 27.03.2026 14:10:58
  • Zuletzt bearbeitet 30.03.2026 17:23:24

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start a...

  • EPSS 0.04%
  • Veröffentlicht 25.11.2025 00:01:17
  • Zuletzt bearbeitet 01.12.2025 15:44:38

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in...

  • EPSS 0.04%
  • Veröffentlicht 22.10.2025 21:23:51
  • Zuletzt bearbeitet 27.10.2025 20:27:05

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is no...

  • EPSS 0.04%
  • Veröffentlicht 22.10.2025 19:18:59
  • Zuletzt bearbeitet 27.10.2025 20:31:53

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using ...