CVE 3.7 LOW

OpenBao: Timing Side-Channel in Userpass Auth Method_CVE-2025-54999

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timing difference between non-existent users and users with stored credentials. This is independent of whether the supplied credentials were valid for the given user. This issue was fixed in version 2.3.2. To work around this issue, users may use another auth method or apply rate limiting quotas to limit the number of requests in a period of time: https://openbao.org/api-docs/system/rate-limit-quotas/.

Basic Information

ID CVE-2025-54999
Source GitHub_M
Published Aug 9, 2025 at 02:00

Affected Product

Vendor openbao
Product openbao
Version >= 0.1.0, < 2.3.2
Affected Versions openbao openbao >= 0.1.0, < 2.3.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.