PT-2025-32381 · Openbao+1 · Openbao+1
Cipherboy
·
Published
2025-08-08
·
Updated
2025-09-12
·
CVE-2025-54999
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenBao versions 0.1.0 through 2.3.1
Description
OpenBao is a software solution designed for managing, storing, and distributing sensitive data, including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, user enumeration was possible when using the userpass authentication method due to timing differences between non-existent users and users with stored credentials. This issue occurred regardless of the validity of the supplied credentials.
Recommendations
OpenBao version 2.3.2 and later resolves this issue.
As a workaround, use an alternative authentication method.
Apply rate limiting quotas to limit the number of requests within a specific timeframe.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao
Red Os