Bitnami package
openbao
pkg:bitnami/openbao
Vulnerabilities (24)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42186 | Hig | 7.5 | < 2.5.3 | 2.5.3 | May 14, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as pote | |
| CVE-2026-40264 | Low | 2.7 | < 2.5.3 | 2.5.3 | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is ad | |
| CVE-2026-39946 | Med | 4.9 | < 2.5.3 | 2.5.3 | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead t | |
| CVE-2026-39396 | Low | 3.1 | < 2.5.3 | 2.5.3 | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy` with no upper bound on the nu | |
| CVE-2026-39388 | Low | 3.1 | < 2.5.3 | 2.5.3 | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matche | |
| CVE-2026-33758 | Med | 6.1 | < 2.5.2 | 2.5.2 | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on | |
| CVE-2026-33757 | Cri | 9.6 | < 2.5.2 | 2.5.2 | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and p | |
| CVE-2025-64761 | Hig | 7.2 | < 2.4.4 | 2.4.4 | Nov 25, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this | |
| CVE-2025-62705 | Med | 4.9 | < 2.4.2 | 2.4.2 | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use | |
| CVE-2025-62513 | Hig | 7.5 | >= 2.2.0, < 2.4.2 | 2.4.2 | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, | |
| CVE-2025-59043 | Hig | 7.5 | < 2.4.1 | 2.4.1 | Oct 17, 2025 | OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize the factor between serialized me | |
| CVE-2025-55003 | Med | 5.7 | < 0.0.0-20250807113757-8340a6918f6c | 0.0.0-20250807113757-8340a6918f6c | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using Time-based One Time Password ( | |
| CVE-2025-55001 | Med | 6.5 | < 0.0.0-20250807212521-c52795c1ef74 | 0.0.0-20250807212521-c52795c1ef74 | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying | |
| CVE-2025-55000 | Med | 6.5 | < 0.0.0-20250806193153-183891f8d535 | 0.0.0-20250806193153-183891f8d535 | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caus | |
| CVE-2025-54999 | Low | 3.7 | < 0.0.0-20250806193356-4d9b5d3d6486 | 0.0.0-20250806193356-4d9b5d3d6486 | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timing difference between non- | |
| CVE-2025-54998 | Med | 5.3 | < 0.0.0-20250807212521-c52795c1ef74 | 0.0.0-20250807212521-c52795c1ef74 | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. Thi | |
| CVE-2025-54997 | Cri | 9.1 | < 0.0.0-20250806194004-a14053c9679d | 0.0.0-20250806194004-a14053c9679d | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making network | |
| CVE-2025-54996 | Hig | 7.2 | < 0.0.0-20250806193240-9b0b5d4f345f | 0.0.0-20250806193240-9b0b5d4f345f | Aug 9, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their s | |
| CVE-2025-52894 | Hig | 7.5 | >= 2.2.2, < 2.3.1 | 2.3.1 | Jun 25, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 allowed an attacker to perform unauthenticated, unaudited cancellation of root rekey and recovery rekey operations, effec | |
| CVE-2025-52893 | Med | 4.5 | < 2.3.0 | 2.3.0 | Jun 25, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data. This is separate from the earlier HCSEC-2025-09 / |
- affected < 2.5.3fixed 2.5.3
OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as pote
- affected < 2.5.3fixed 2.5.3
OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is ad
- affected < 2.5.3fixed 2.5.3
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead t
- affected < 2.5.3fixed 2.5.3
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy` with no upper bound on the nu
- affected < 2.5.3fixed 2.5.3
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matche
- affected < 2.5.2fixed 2.5.2
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on
- affected < 2.5.2fixed 2.5.2
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and p
- affected < 2.4.4fixed 2.4.4
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this
- affected < 2.4.2fixed 2.4.2
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use
- affected >= 2.2.0, < 2.4.2fixed 2.4.2
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI,
- affected < 2.4.1fixed 2.4.1
OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize the factor between serialized me
- affected < 0.0.0-20250807113757-8340a6918f6cfixed 0.0.0-20250807113757-8340a6918f6c
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using Time-based One Time Password (
- affected < 0.0.0-20250807212521-c52795c1ef74fixed 0.0.0-20250807212521-c52795c1ef74
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying
- affected < 0.0.0-20250806193153-183891f8d535fixed 0.0.0-20250806193153-183891f8d535
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caus
- affected < 0.0.0-20250806193356-4d9b5d3d6486fixed 0.0.0-20250806193356-4d9b5d3d6486
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timing difference between non-
- affected < 0.0.0-20250807212521-c52795c1ef74fixed 0.0.0-20250807212521-c52795c1ef74
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. Thi
- affected < 0.0.0-20250806194004-a14053c9679dfixed 0.0.0-20250806194004-a14053c9679d
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making network
- affected < 0.0.0-20250806193240-9b0b5d4f345ffixed 0.0.0-20250806193240-9b0b5d4f345f
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their s
- affected >= 2.2.2, < 2.3.1fixed 2.3.1
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 allowed an attacker to perform unauthenticated, unaudited cancellation of root rekey and recovery rekey operations, effec
- affected < 2.3.0fixed 2.3.0
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data. This is separate from the earlier HCSEC-2025-09 /
Page 1 of 2