GHSA-444v-8vxr-p36hLow
OpenBao Agent Writes Secrets to Stdout
🔗 CVE IDs covered (1)
📋 Description
Impact
During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in env_template to stdout. This primarily happens when num_retries is met.
This vulnerability is original to Vault and was reported via the OpenBao security mailing list.
Patches
This is addressed in OpenBao v2.6.0 GA.
🎯 Affected products2
- go/github.com/openbao/openbao:< 0.0.0-20260714163218-90272575e5f5
- go/github.com/openbao/openbao:>= 0.1.0, <= 1.1.5
🔗 References (7)
- https://github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36h
- https://github.com/openbao/openbao/pull/3494
- https://github.com/openbao/openbao/pull/3495
- https://github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1a
- https://github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878
- https://github.com/openbao/openbao/releases/tag/v2.6.0
- https://github.com/advisories/GHSA-444v-8vxr-p36h