CVE-2026-77285
BilinmiyorTeknik Veri (Otomatik)
- CVSS Skoru
- —
- EPSS
- —
- CWE
- CWE-532
- KEV Durumu
- Hayır
OpenBao, açık kaynaklı bir kimlik tabanlı sırlar yönetim sistemidir. 2.6.0 sürümünden önce, OpenBao Aracısı'nın exec rendering modu, komut/agent/exec/exec.go tekrar edilen rendering hatalarından sonra şablon çalıştırıcısını yeniden oluşturduğunda, principalmente num_retries sınırına ulaşıldığında, env_template'den sırları standart çıktıya yazabilirdi. Bir süreç denetçisi, günlük kolektörü veya o çıktıyı okuyabilen yerel bir kullanıcı, oluşturulan gizli değerleri elde edebilirdi. Bu sorun 2.6.0 sürümünde giderilmiştir.
Orijinal açıklama (İngilizce)
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that output could obtain the rendered secret values. This issue is fixed in version 2.6.0.
Referanslar
- https://github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1a
- https://github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878
- https://github.com/openbao/openbao/pull/3494
- https://github.com/openbao/openbao/pull/3495
- https://github.com/openbao/openbao/releases/tag/v2.6.0
- https://github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36h
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
