VYPR

Bitnami package

openbao

pkg:bitnami/openbao

Vulnerabilities (24)

  • CVE-2025-4166MedMay 2, 2025
    affected < 2.2.2fixed 2.2.2

    Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified a

  • CVE-2024-8185HigOct 31, 2024
    affected < 2.0.3fixed 2.0.3

    Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint

  • CVE-2024-9180HigOct 10, 2024
    affected < 2.0.3fixed 2.0.3

    A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

  • CVE-2024-7594HigSep 26, 2024
    affected < 2.0.2fixed 2.0.2

    Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engin

Page 2 of 2