GHSA-rc54-2g2c-g36g

    Dashboard / Vulnerabilities / GHSA-rc54-2g2c-g36g

    GHSA-rc54-2g2c-g36g

    Published: 22 Oct 2025Last Modified: 27 Jul 2026

    Summary: OpenBao and Vault Leak []byte Fields in Audit Logs

    Details: ### Impact OpenBao's audit log did not appropriately redact fields when relevant subsystems sent `[]byte` response parameters rather than `string`s. This includes, but is not limited to: - `sys/raw` with use of `encoding=base64`, all data would be emitted unredacted to the audit log. - Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. Third-party plugins may be affected. This issue has been present since HashiCorp Vault and continues to impact Vault as of v1.20.4. ### Patches OpenBao v2.4.2 will patch this issue. ### Workarounds If users do not use the above functionality, they are not impacted. To prohibit the use of `sys/raw` globally, ensure `raw_storage_endpoint=false` is set or missing from the server configuration.

    Affected packages

    Package

    Name: github.com/openbao/openbao

    Purl: pkg:golang/github.com/openbao/openbao

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.0-20251022165510-cc2c476bac66

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rc54-2g2c-g36g | CVE-DB