Openbao

Openbao

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 25.11.2025 00:01:17
  • Zuletzt bearbeitet 01.12.2025 15:44:38

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in...

  • EPSS 0.04%
  • Veröffentlicht 22.10.2025 21:23:51
  • Zuletzt bearbeitet 27.10.2025 20:27:05

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is no...

  • EPSS 0.04%
  • Veröffentlicht 22.10.2025 19:18:59
  • Zuletzt bearbeitet 27.10.2025 20:31:53

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using ...

  • EPSS 0.13%
  • Veröffentlicht 17.10.2025 16:15:38
  • Zuletzt bearbeitet 24.10.2025 17:13:10

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize th...

  • EPSS 0.07%
  • Veröffentlicht 09.08.2025 02:01:43
  • Zuletzt bearbeitet 12.08.2025 20:39:40

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using ...

  • EPSS 0.03%
  • Veröffentlicht 09.08.2025 02:01:29
  • Zuletzt bearbeitet 12.08.2025 20:44:04

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity ali...

  • EPSS 0.03%
  • Veröffentlicht 09.08.2025 02:01:16
  • Zuletzt bearbeitet 13.11.2025 17:55:51

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather tha...

  • EPSS 0.03%
  • Veröffentlicht 09.08.2025 02:00:46
  • Zuletzt bearbeitet 13.11.2025 17:54:56

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to ...

  • EPSS 0.06%
  • Veröffentlicht 09.08.2025 02:00:27
  • Zuletzt bearbeitet 13.11.2025 17:51:59

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao User...

  • EPSS 0.12%
  • Veröffentlicht 09.08.2025 01:56:45
  • Zuletzt bearbeitet 13.08.2025 18:23:12

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing...