BIT-openbao-2025-54999

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/openbao/BIT-openbao-2025-54999.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-openbao-2025-54999
Aliases
Published
2026-07-27T05:48:54Z
Modified
2026-09-08T08:47:45Z
Summary
OpenBao: Timing Side-Channel in Userpass Auth Method
Details

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timing difference between non-existent users and users with stored credentials. This is independent of whether the supplied credentials were valid for the given user. This issue was fixed in version 2.3.2. To work around this issue, users may use another auth method or apply rate limiting quotas to limit the number of requests in a period of time: https://openbao.org/api-docs/system/rate-limit-quotas/.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:openbao:openbao:*:*:*:*:*:go:*:*"
    ],
    "severity":  "Low"
}
References

Affected packages

Bitnami / openbao

Package

Name
openbao
Purl
pkg:bitnami/openbao

Severity

  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20250806193356-4d9b5d3d6486
Introduced
0.0.1
Fixed
2.3.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/openbao/BIT-openbao-2025-54999.json"