PT-2025-26866 · Openbao · Openbao

Cipherboy

·

Publicado

2025-06-25

·

Atualizado

2025-08-12

·

CVE-2025-52894

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: OpenBao versions prior to 2.3.0
Description: OpenBao is a software solution for managing, storing, and distributing sensitive data, including secrets, certificates, and keys. The issue allows an attacker to perform unauthenticated, unaudited cancellation of root rekey and recovery rekey operations, resulting in a denial of service.
Recommendations: For OpenBao versions prior to 2.3.0, manually set the configuration option disable unauthed rekey endpoints=true to deny these endpoints on global listeners. As a temporary workaround, if an active proxy or load balancer sits in front of OpenBao, consider denying requests to these endpoints from unauthorized IP ranges. Update to version 2.3.0 or later, where the issue is resolved.

Exploit

Correção

DoS

Missing Authentication

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-52894
GHSA-PRPJ-RCHP-9J5H
GO-2025-3783
OPENSUSE-SU-2025:15254-1
OPENSUSE-SU-2025:15405-1

Produtos afetados

Openbao