OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. This was caused by different aliasing between pre-flight and full login request user entity alias attributions. This is fixed in version 2.3.2. To work around this issue, existing users may apply rate-limiting quotas on the authentication endpoints:, see https://openbao.org/api-docs/system/rate-limit-quotas/.
History

Tue, 12 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Openbao
Openbao openbao
CPEs cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*
Vendors & Products Openbao
Openbao openbao

Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Openbao Project
Openbao Project openbao
Vendors & Products Openbao Project
Openbao Project openbao

Mon, 11 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 09 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
Description OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems. This was caused by different aliasing between pre-flight and full login request user entity alias attributions. This is fixed in version 2.3.2. To work around this issue, existing users may apply rate-limiting quotas on the authentication endpoints:, see https://openbao.org/api-docs/system/rate-limit-quotas/.
Title OpenBao Userpass and LDAP User Lockout Bypass
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-09T02:00:27.597Z

Updated: 2025-08-11T14:38:33.591Z

Reserved: 2025-08-04T17:34:24.420Z

Link: CVE-2025-54998

cve-icon Vulnrichment

Updated: 2025-08-11T14:38:25.068Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-09T03:15:46.463

Modified: 2025-08-12T20:50:55.900

Link: CVE-2025-54998

cve-icon Redhat

No data.