Vulnerabilidades em openbao
32 resultadosAnálise Vexday
OpenBao possui 21 vulnerabilidades no registro com 3 críticas, mas nenhuma sob exploração ativa conhecida. A fraqueza predominante (CWE-532: Log Information Disclosure) sugere exposição de dados sensíveis em logs, risco moderado para ambientes com auditoria rigorosa. O volume reduzido de descobertas recentes (1 em 90 dias) indica maturidade relativa do produto, mas exige atenção contínua às críticas catalogadas.
CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2025-54996HIGHOpenBao Root Namespace Operator May Elevate Token PrivilegesEPSS 0.3%CVE-2025-52893MEDIUMOpenBao May Leak Sensitive Information in Logs When Processing Malformed DataEPSS 0.3%CVE-2025-59048HIGHOpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth MethodEPSS 0.3%CVE-2025-55003MEDIUMOpenBao Login MFA Bypasses Rate Limiting and TOTP Token ReuseEPSS 0.2%CVE-2025-55001MEDIUMOpenBao LDAP MFA Enforcement Bypass When Using Username As AliasEPSS 0.2%CVE-2025-55000MEDIUMOpenBao TOTP Secrets Engine Enables Code ReuseEPSS 0.2%CVE-2025-54998MEDIUMOpenBao Userpass and LDAP User Lockout BypassEPSS 0.2%CVE-2026-46358MEDIUMOpenBao's Inline Auth Incorrectly Redacted HeadersEPSS 0.2%CVE-2025-54999LOWOpenBao: Timing Side-Channel in Userpass Auth MethodEPSS 0.2%CVE-2026-39388LOWOpenBao's Certificate Authentication Allows Token Renewal With Different CertificateEPSS 0.1%CVE-2026-77285LOWOpenBao Agent Writes Secrets to StdoutEPSS 0.1%