Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7ff4-jw48-3436

Опубликовано: 24 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.5

Описание

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

Impact

Similar to HCSEC-2025-13 / CVE-2025-5999, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when:

  1. An operator in the root namespace has access to identity/groups endpoints.
  2. An operator does not have policy access.

Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability.

Patches

Patched in version 2.4.4.

Workarounds

Users should audit the use of identity subsystem and deny operators access if it is not in use.

Пакеты

Наименование

github.com/openbao/openbao

go
Затронутые версииВерсия исправления

< 2.4.4

2.4.4

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS4

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 7.2
nvd
2 месяца назад

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability. This issue has been patched in version 2.4.4.

CVSS3: 7.2
debian
2 месяца назад

OpenBao is an open source identity-based secrets management system. Pr ...

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS4

Дефекты

CWE-266
CWE-269