PT-2025-47976 · Openbao+1 · Openbao+1
Publicado
2025-11-24
·
Atualizado
2026-03-19
·
CVE-2025-64761
CVSS v4.0
7.5
Alta
| Vetor | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.4.4
Description
OpenBao is an identity-based secrets management system. A privileged operator could leverage the identity group subsystem to add a root policy to a group identity group, potentially escalating their own or another user's permissions. This occurs when an operator in the root namespace has access to identity/groups endpoints and lacks policy access. An operator with policy access could also create or modify a policy to grant root-equivalent permissions using the sudo capability. The issue involves the
/identity/groups API endpoint.Recommendations
Update to version 2.4.4 or later.
Exploit
Correção
LPE
Incorrect Privilege Assignment
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openbao
Red Os