Количество 6
Количество 6
CVE-2026-33757
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.
CVE-2026-33757
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.
CVE-2026-33757
OpenBao is an open source identity-based secrets management system. Pr ...
GHSA-7q7g-x6vg-xpc3
OpenBao lacks user confirmation for OIDC direct callback mode
BDU:2026-08727
Уязвимость метода аутентификации JWT/OIDC системы управления секретами и шифрованием OpenBao, позволяющая нарушителю перехватить сеанс пользователя
ROS-20260529-73-0015
Уязвимость openbao
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33757 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao. | CVSS3: 9.6 | 0% Низкий | 4 месяца назад | |
CVE-2026-33757 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao. | CVSS3: 9.6 | 0% Низкий | 4 месяца назад | |
CVE-2026-33757 OpenBao is an open source identity-based secrets management system. Pr ... | CVSS3: 9.6 | 0% Низкий | 4 месяца назад | |
GHSA-7q7g-x6vg-xpc3 OpenBao lacks user confirmation for OIDC direct callback mode | CVSS3: 9.6 | 0% Низкий | 4 месяца назад | |
BDU:2026-08727 Уязвимость метода аутентификации JWT/OIDC системы управления секретами и шифрованием OpenBao, позволяющая нарушителю перехватить сеанс пользователя | CVSS3: 9.6 | 0% Низкий | 4 месяца назад | |
ROS-20260529-73-0015 Уязвимость openbao | CVSS3: 8.3 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу