CVE-2026-77285
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that output could obtain the rendered secret values. This issue is fixed in version 2.6.0.
Kelemahan
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that output could obtain the rendered secret values. This issue is fixed in version 2.6.0.
Referensi
- https://github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1a
- https://github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878
- https://github.com/openbao/openbao/pull/3494
- https://github.com/openbao/openbao/pull/3495
- https://github.com/openbao/openbao/releases/tag/v2.6.0
- https://github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36h
Temukan bug sebelum penyerang menemukannya.
Masuk dengan GitHub dan jalankan audit pertama Anda dalam waktu kurang dari satu menit. Paket gratis tidak memerlukan kartu kredit.