Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-55000

Опубликовано: 09 авг. 2025
Источник: debian
EPSS Низкий

Описание

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caused by unexpected normalization in the underlying TOTP library. To work around, ensure that all codes are first normalized before submitting to the OpenBao endpoint. TOTP code verification is a privileged action; only trusted systems should be verifying codes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openbaoitppackage

EPSS

Процентиль: 4%
0.0002
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caused by unexpected normalization in the underlying TOTP library. To work around, ensure that all codes are first normalized before submitting to the OpenBao endpoint. TOTP code verification is a privileged action; only trusted systems should be verifying codes.

CVSS3: 6.5
github
около 1 месяца назад

OpenBao TOTP Secrets Engine Code Reuse

EPSS

Процентиль: 4%
0.0002
Низкий