Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv66-6rp4-wr4f

Опубликовано: 05 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3

Описание

OpenBao's Namespace Deletion May Not Delete Data Properly

Impact

When OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around.

Patches

This will be patched in OpenBao v2.5.3.

Workarounds

Users may manually remove mounts prior to deleting the namespace.

Audit logs may be used to identify repeated deletion attempts against the same namespace; sys/raw can be used to see what leases were not correctly deleted.

Пакеты

Наименование

github.com/openbao/openbao

go
Затронутые версииВерсия исправления

< 0.0.0-20260420173541-6d2e0506e2b4

0.0.0-20260420173541-6d2e0506e2b4

EPSS

Процентиль: 16%
0.00248
Низкий

2.3 Low

CVSS4

Дефекты

CWE-212

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.

CVSS3: 7.5
debian
3 месяца назад

OpenBao is an open source identity-based secrets management system. Pr ...

CVSS3: 3.5
redos
около 1 месяца назад

Уязвимость openbao

CVSS3: 3.5
fstec
3 месяца назад

Уязвимость файла vault/namespace_store.go ядра системы управления секретами и шифрованием OpenBao, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 16%
0.00248
Низкий

2.3 Low

CVSS4

Дефекты

CWE-212