Information Exposure Through Log Files Affecting openbao package, versions <2.4.3-r0


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.31% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE323-OPENBAO-14182557
  • published4 Dec 2025
  • disclosed22 Oct 2025

Introduced: 22 Oct 2025

CVE-2025-62705  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade Alpine:3.23 openbao to version 2.4.3-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream openbao package and not the openbao package as distributed by Alpine. See How to fix? for Alpine:3.23 relevant fixed versions and status.

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.

CVSS Base Scores

version 3.1