Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-54998


OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. This was caused by different aliasing between pre-flight and full login request user entity alias attributions. This is fixed in version 2.3.2. To work around this issue, existing users may apply rate-limiting quotas on the authentication endpoints:, see https://openbao.org/api-docs/system/rate-limit-quotas/.


Published

2025-08-09T03:15:46.463

Last Modified

2025-11-13T17:51:59.120

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-307

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openbao openbao < 2.3.2 Yes

References