Impact
OpenBao is an open source identity‑based secrets management system. Prior to version 2.5.5, OpenBao uses the RFC 4514 EscapeLDAPValue function to build LDAP search filters, although RFC 4515 LDAP search‑filter escaping is required in the GetUserDN helper. When the LDAP authentication backend is configured for an Active Directory UPNDomain path, or with UserDN and UserAttr bindings, a malicious username containing LDAP filter metacharacters can alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. The resulting authentication token becomes associated with another LDAP identity, granting the attacker access to secrets, policies, or modification capabilities tied to that identity. The vulnerability is fixed in OpenBao 2.5.5.
Affected Systems
OpenBao versions prior to 2.5.5, including all 1.x and 2.x releases, are affected when the LDAP authentication backend is configured with an Active Directory UPNDomain path, or with UserDN or UserAttr bindings. Any deployment that relies on LDAP for user lookup in these configurations is vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. The EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker to supply a malicious username to the LDAP authentication endpoint, so the exploit can be performed over the network if that interface is reachable. Successful exploitation results in a valid authentication token that maps to an unintended LDAP identity, thereby granting the attacker the permissions assigned to that identity.
OpenCVE Enrichment
Github GHSA