Brute Force Affecting github.com/openbao/openbao/builtin/credential/ldap package, versions <2.3.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Brute Force vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMOPENBAOOPENBAOBUILTINCREDENTIALLDAP-11735309
  • published10 Aug 2025
  • disclosed9 Aug 2025
  • creditUnknown

Introduced: 9 Aug 2025

NewCVE-2025-54998  (opens in a new tab)
CWE-307  (opens in a new tab)

How to fix?

Upgrade github.com/openbao/openbao/builtin/credential/ldap to version 2.3.2 or higher.

Overview

Affected versions of this package are vulnerable to Brute Force via the authentication process in the Userpass or LDAP systems. An attacker can circumvent intended user lockout protections by exploiting differences in user entity alias attribution between pre-flight and full login requests. This allows repeated authentication attempts without triggering lockout mechanisms.

Workaround

This vulnerability can be mitigated by applying rate-limiting quotas on the authentication endpoints.

CVSS Base Scores

version 4.0
version 3.1