Ad

CVE-2025-62705

MEDIUM CVSS 3.1: 4.9 EPSS 0.04%
Updated Oct 27, 2025
Openbao
Parameter Value
CVSS 4.9 (MEDIUM)
Affected Versions before 2.4.2
Fixed In 2.4.2
Type CWE-532
Vendor Openbao
Public PoC No

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log.

This issue has been patched in OpenBao 2.4.2.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Openbao Openbao
cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*
2.4.2