PT-2025-26865 · Openbao · Openbao
Cipherboy
·
Published
2025-06-25
·
Updated
2025-08-12
·
CVE-2025-52893
CVSS v3.1
4.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenBao versions prior to 2.3.0
Description:
The issue concerns the potential leak of sensitive information in logs when processing malformed data. This problem has been identified in OpenBao, a software solution designed to manage, store, and distribute sensitive data, including secrets, certificates, and keys. There are no known real-world incidents or estimated numbers of affected devices mentioned.
Recommendations:
For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue. As a temporary workaround, ensure properly formatted requests from all clients to minimize the risk of sensitive information leakage.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao