Insecurely generated token In github.com/openbao/openbao
Description
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Impact
OpenBao's namespaces provide multi-tenant separation. A tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant.
Patches
This was addressed in v2.5.3.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.0.0-20260420162526-f58111d2ca54 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.