Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-24037 | Privileged OpenBao Operator May Execute Code on the Underlying Host |
![]() |
GHSA-xp75-r577-cvhp | Privileged OpenBao Operator May Execute Code on the Underlying Host |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openbao
Openbao openbao |
|
CPEs | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openbao
Openbao openbao |
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openbao Project
Openbao Project openbao |
|
Vendors & Products |
Openbao Project
Openbao Project openbao |
Mon, 11 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making network connections. However, these operators can bypass both restrictions through the audit subsystem by manipulating log prefixes. This allows unauthorized code execution and network access that violates the intended security model. This issue is fixed in version 2.3.2. To workaround, users can block access to sys/audit/* endpoints using explicit deny policies, but root operators cannot be restricted this way. | |
Title | OpenBao: Privileged Operator May Execute Code on the Underlying Host | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-11T13:56:43.049Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54997

Updated: 2025-08-11T13:56:35.007Z

Status : Analyzed
Published: 2025-08-09T03:15:46.263
Modified: 2025-08-13T18:23:12.113
Link: CVE-2025-54997

No data.

Updated: 2025-08-12T11:47:15Z