9.2 CRITICAL
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response timing could infer the recovery token. The recovered token could then authorize recovery mode operations that read or modify OpenBao data. This issue is fixed in version 2.6.0.
References
-
https://github.com/openbao/openbao/security/advisories/GHSA-34fc-gh42-pj53 x_refsource_CONFIRM
-
https://github.com/openbao/openbao/pull/3388 x_refsource_MISC
-
https://github.com/openbao/openbao/pull/3472 x_refsource_MISC
-
https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203 x_refsource_MISC
-
https://github.com/openbao/openbao/releases/tag/v2.6.0 x_refsource_MISC
Affected products
- ==< 2.6.0
Matching in nixpkgs
pkgs.openbao
Open source, community-driven fork of Vault managed by the Linux Foundation
pkgs.openbaoPlugins.kms-aws
OpenBao KMS plugin for Auto Unseal via AWS
-
nixos-unstable -
- nixos-unstable-small 0.1.0
pkgs.openbaoPlugins.kms-gcp
OpenBao KMS plugin for Auto Unseal via Google Cloud
-
nixos-unstable -
- nixos-unstable-small 0.1.0
pkgs.openbaoPlugins.kms-oci
OpenBao KMS plugin for Auto Unseal via Oracle Cloud
-
nixos-unstable -
- nixos-unstable-small 0.1.0
pkgs.openbaoPlugins.auth-aws
OpenBao auth plugin to authenticate using AWS IAM credentials
-
nixos-unstable -
- nixos-unstable-small 0.1.1
pkgs.openbaoPlugins.auth-gcp
OpenBao auth plugin to authenticate using Google Cloud Platform credentials
-
nixos-unstable -
- nixos-unstable-small 0.22.0
pkgs.openbaoPlugins.kms-azure
OpenBao KMS plugin for Auto Unseal via Azure
-
nixos-unstable -
- nixos-unstable-small 0.1.0
pkgs.openbaoPlugins.auth-azure
OpenBao auth plugin to authenticate using Microsoft Azure credentials
-
nixos-unstable -
- nixos-unstable-small 0.23.0
pkgs.openbaoPlugins.kms-pkcs11
OpenBao KMS plugin for Auto Unseal and External Keys via PKCS#11
-
nixos-unstable -
- nixos-unstable-small 0.2.1
pkgs.openbaoPlugins.auth-github
OpenBao auth plugin to authenticate using GitHub credentials
-
nixos-unstable -
- nixos-unstable-small 0.0.1
pkgs.openbaoPlugins.secrets-aws
OpenBao secrets plugin to generate AWS access credentials based on IAM policies
-
nixos-unstable -
- nixos-unstable-small 0.3.1
pkgs.openbaoPlugins.secrets-gcp
OpenBao secrets plugin to generate GCP service account keys and OAuth tokens based on IAM policies
-
nixos-unstable -
- nixos-unstable-small 0.23.1
pkgs.openbaoPlugins.kms-alicloud
OpenBao KMS plugin for Auto Unseal via AliCloud
-
nixos-unstable -
- nixos-unstable-small 0.1.1
pkgs.openbaoPlugins.kms-ovhcloud
OpenBao KMS plugin for Auto Unseal via OVHcloud
-
nixos-unstable -
- nixos-unstable-small 0.0.1
pkgs.openbaoPlugins.secrets-azure
OpenBao secrets plugin to generate Azure service principals with role and group assignments
-
nixos-unstable -
- nixos-unstable-small 0.23.0
pkgs.openbaoPlugins.secrets-nomad
OpenBao secrets plugin to generate Nomad ACL tokens
-
nixos-unstable -
- nixos-unstable-small 0.1.6
pkgs.openbaoPlugins.secrets-consul
OpenBao secrets plugin to generate Consul ACL tokens
-
nixos-unstable -
- nixos-unstable-small 0.1.1
pkgs.openbaoPlugins.secrets-gcpkms
OpenBao secrets plugin to encrypt data and manage keys via GCP KMS
-
nixos-unstable -
- nixos-unstable-small 0.21.0
pkgs.openbaoPlugins.database-mongodb
OpenBao database plugin to generate MongoDB database credentials
-
nixos-unstable -
- nixos-unstable-small 0.0.1
pkgs.openbaoPlugins.kms-tcloudpublic
OpenBao KMS plugin for Auto Unseal via T Cloud Public
-
nixos-unstable -
- nixos-unstable-small 0.0.1
pkgs.openbaoPlugins.secrets-oauthapp
OpenBao secrets plugin for OAuth 2.0 supporting a variety of grant types
-
nixos-unstable -
- nixos-unstable-small 3.4.0
Package maintainers
-
@emilylange Emily Lange <nix@emilylange.de>
-
@brianmay Brian May <brian@linuxpenguins.xyz>
-
@Kranzes Ilan Joselevich <personal@ilanjoselevich.com>