VDB
EN
HIGH

GHSA-v8v8-cm84-m686

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

상세

# Impact

OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints.

# Patch

This will be addressed in v2.5.4.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Go / github.com/openbao/openbao
최초 영향 버전: 0 수정 버전: 2.5.4
수정 go get github.com/openbao/openbao@v2.5.4

참고