Impact
OpenBao's inline authentication facility fails to correctly redact audit log entries, a flaw identified as CWE-532. The incorrect redaction removes non‑authentication headers from logs while leaving authentication‑related headers in cleartext. This results in the exposure of sensitive authentication data within the audit trail. The vulnerability allows an attacker to read privileged authentication information that should have been masked, potentially enabling credential theft and subsequent system compromise.
Affected Systems
The issue affects all OpenBao installations running a version earlier than 2.5.4. The OpenBao product is distributed by the openbao organization. Operators of any such affected deployment should verify the version in use and plan for upgrade.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the exploit probability (EPSS) data is not available, with the vulnerability not listed in the CISA KEV catalog. Exploitation requires an attacker to gain access to the audit device or system that stores the audit logs. Once access is achieved, the attacker can read the unredacted authentication information without additional privileges.
OpenCVE Enrichment
Github GHSA