Количество 6
Количество 6
CVE-2026-39946
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
CVE-2026-39946
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
CVE-2026-39946
OpenBao is an open source identity-based secrets management system. Pr ...
GHSA-6vgr-cp5c-ffx3
OpenBao's SQL Injection in PostgreSQL database secrets engine
BDU:2026-08724
Уязвимость системы управления секретами и шифрованием OpenBao, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код
ROS-20260527-73-0004
Уязвимость openbao
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39946 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them. | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-39946 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them. | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-39946 OpenBao is an open source identity-based secrets management system. Pr ... | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
GHSA-6vgr-cp5c-ffx3 OpenBao's SQL Injection in PostgreSQL database secrets engine | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
BDU:2026-08724 Уязвимость системы управления секретами и шифрованием OpenBao, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
ROS-20260527-73-0004 Уязвимость openbao | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу