Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45808

Опубликовано: 07 авг. 2026
Источник: debian

Описание

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openbaoitppackage

Связанные уязвимости

nvd
6 дней назад

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.

github
3 месяца назад

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

CVSS3: 6.5
redos
около 1 месяца назад

Уязвимость openbao

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость системы управления секретами и шифрованием OpenBao, связанная с недостатками контроля доступа, позволяющая нарушителю повысить свои привилегии