Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-55001


OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When the username_as_alias=true parameter in the LDAP auth method was in use, the caller-supplied username was used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements. This issue was fixed in version 2.3.2. To work around this, remove all usage of the username_as_alias=true parameter and update any entity aliases accordingly.


Published

2025-08-09T03:15:46.887

Last Modified

2025-08-12T20:44:04.173

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-156

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openbao openbao < 2.3.2 Yes

References