Skip to content

x/vulndb: potential Go vuln in github.com/openbao/openbao: GHSA-rc54-2g2c-g36g #4052

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-rc54-2g2c-g36g references a vulnerability in the following Go modules:

Module
github.com/openbao/openbao

Description:

Impact

OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to:

  • sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log.
  • Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log.

Third-party plugins may be affected.

This issue has been present since HashiCorp Vault and continues to impact Vault as of v1.20.4.

Patches

OpenBao v2.4.2 will patch this issue.

Worka...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/openbao/openbao
      versions:
        - fixed: 0.0.0-20251022165510-cc2c476bac66
summary: OpenBao and Vault Leak []byte Fields in Audit Logs in github.com/openbao/openbao
cves:
    - CVE-2025-62705
ghsas:
    - GHSA-rc54-2g2c-g36g
references:
    - advisory: https://github.com/advisories/GHSA-rc54-2g2c-g36g
    - advisory: https://github.com/openbao/openbao/security/advisories/GHSA-rc54-2g2c-g36g
    - fix: https://github.com/openbao/openbao/commit/cc2c476bac66e1d94776c2629793daec3af625f8
notes:
    - fix: 'github.com/openbao/openbao: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
    id: GHSA-rc54-2g2c-g36g
    created: 2025-10-22T20:01:44.206051188Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions