HIGH
GHSA-v8v8-cm84-m686
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
상세
# Impact
OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints.
# Patch
This will be addressed in v2.5.4.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Go / github.com/openbao/openbao
최초 영향 버전:
0 수정 버전: 2.5.4 수정
go get github.com/openbao/openbao@v2.5.4 참고
- https://github.com/openbao/openbao/security/advisories/GHSA-v8v8-cm84-m686 [WEB]
- https://github.com/openbao/openbao/pull/3152 [WEB]
- https://github.com/openbao/openbao/commit/c0495646b41cea0e3f5a1030132e9cf5c2375b5c [WEB]
- https://github.com/openbao/openbao [PACKAGE]
- https://github.com/openbao/openbao/releases/tag/v2.5.4 [WEB]