Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8cj-789h-vg24

Опубликовано: 28 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.4

Описание

OpenBao's Inline Auth Incorrectly Redacted Headers

Impact

OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate.

Patches

This is fixed in OpenBao v2.5.4.

Resources

https://github.com/openbao/openbao/issues/3074

Пакеты

Наименование

github.com/openbao/openbao

go
Затронутые версииВерсия исправления

<= 2.5.3

2.5.4

5.4 Medium

CVSS4

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.7
redos
24 дня назад

Уязвимость openbao

5.4 Medium

CVSS4

Дефекты

CWE-532