PT-2025-32381 · Openbao+1 · Openbao+1

Cipherboy

·

Published

2025-08-08

·

Updated

2025-09-12

·

CVE-2025-54999

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenBao versions 0.1.0 through 2.3.1
Description OpenBao is a software solution designed for managing, storing, and distributing sensitive data, including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, user enumeration was possible when using the userpass authentication method due to timing differences between non-existent users and users with stored credentials. This issue occurred regardless of the validity of the supplied credentials.
Recommendations OpenBao version 2.3.2 and later resolves this issue. As a workaround, use an alternative authentication method. Apply rate limiting quotas to limit the number of requests within a specific timeframe.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11277
CVE-2025-54999
GHSA-HH28-H22F-8357
GO-2025-3854
OPENSUSE-SU-2025:15434-1
SUSE-SU-2025:02912-1

Affected Products

Openbao
Red Os