Openbao

Openbao

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 07.08.2026 20:32:36
  • Zuletzt bearbeitet 09.09.2026 21:02:22

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retaine...

  • EPSS 0.25%
  • Veröffentlicht 14.05.2026 14:36:14
  • Zuletzt bearbeitet 18.05.2026 14:10:48

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outs...

  • EPSS 0.3%
  • Veröffentlicht 21.04.2026 00:47:38
  • Zuletzt bearbeitet 24.04.2026 13:29:24

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.04.2026 00:44:53
  • Zuletzt bearbeitet 01.05.2026 16:36:07

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy`...

  • EPSS 0.1%
  • Veröffentlicht 21.04.2026 00:43:22
  • Zuletzt bearbeitet 24.04.2026 13:27:34

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's pre...

  • EPSS 0.24%
  • Veröffentlicht 21.04.2026 00:19:39
  • Zuletzt bearbeitet 24.04.2026 13:28:39

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by...

  • EPSS 0.29%
  • Veröffentlicht 27.03.2026 14:12:33
  • Zuletzt bearbeitet 15.07.2026 02:20:15

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `er...

  • EPSS 0.41%
  • Veröffentlicht 27.03.2026 14:10:58
  • Zuletzt bearbeitet 15.07.2026 02:20:15

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start a...

  • EPSS 0.35%
  • Veröffentlicht 25.11.2025 00:01:17
  • Zuletzt bearbeitet 01.12.2025 15:44:38

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in...

  • EPSS 0.31%
  • Veröffentlicht 22.10.2025 21:23:51
  • Zuletzt bearbeitet 27.10.2025 20:27:05

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is no...