GHSA-xp3c-3jw3-4vcrMedium
OpenBao Skips Stricter Deny Policy for LIST operations
🔗 CVE IDs covered (1)
📋 Description
Impact
When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.
Patches
This has been patched in OpenBao v2.6.0.
🎯 Affected products2
- go/github.com/openbao/openbao:< 0.0.0-20260713133043-f58d848c139e
- go/github.com/openbao/openbao:>= 0.1.0, <= 1.1.5
🔗 References (8)
- https://github.com/openbao/openbao/security/advisories/GHSA-xp3c-3jw3-4vcr
- https://github.com/openbao/openbao/pull/3389
- https://github.com/openbao/openbao/pull/3474
- https://github.com/openbao/openbao/commit/2e9625d6cebe4639d051ef53dd6ce7c49914ae6a
- https://github.com/openbao/openbao/commit/f58d848c139e5ba71aa63103fcfe101972b999fc
- https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203
- https://github.com/openbao/openbao/releases/tag/v2.6.0
- https://github.com/advisories/GHSA-xp3c-3jw3-4vcr