OpenBao 是一个基于身份的开源密钥管理系统。在 2.5.5 版本之前,OpenBao 在 中的 函数中使用了 函数(该函数用于 RFC 4514 指定名称的转义),但此处实际需要进行的是 RFC 4515 定义的 LDAP 搜索过滤器转义。 当 LDAP 认证后端配置为 Active Directory 的 UPNDomain 路径,或使用 UserDN 和 UserAttr 进行绑定时,攻击者若控制包含过滤器元字符(filter metacharacters)的用户名,就可能篡改搜索谓词,从而选中另一个目录
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55776 | 6.5 MEDIUM | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetri |
| CVE-2026-55775 | 2.3 LOW | OpenBao's System Backend allows Unauthorized Management of the containing Namespace |
| CVE-2026-55774 | 2.1 LOW | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} |
No comments yet