PT-2025-43411 · Hashicorp+2 · Hashicorp Vault+2

Publicado

2025-10-22

·

Atualizado

2025-11-28

·

CVE-2025-62705

CVSS v4.0

5.7

Média

VetorAV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.4.2
Description The audit log in OpenBao did not properly redact sensitive fields when subsystems sent byte arrays instead of strings as response parameters. This affected functionalities such as sys/raw with base64 encoding, where all data was written unredacted to the audit log. Additionally, when using Transit for Ed25519 key signing operations, public keys were exposed in the audit log. Third-party plugins may also be affected. The issue impacts versions of HashiCorp Vault as of v1.20.4. The vulnerable parameters include []byte response parameters and derived Ed25519 public keys. The affected API endpoint is /sys/raw.
Recommendations Update to OpenBao version 2.4.2 to address this issue. To prevent the use of the /sys/raw endpoint, ensure raw storage endpoint=false is set or missing from the server configuration.

Exploit

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62705
GHSA-RC54-2G2C-G36G
GO-2025-4052
OPENSUSE-SU-2025:15663-1
OPENSUSE-SU-2025:15710-1

Produtos afetados

Hashicorp Vault
Openbao
Red Os