CVE-2025-62513
Last modified
CVE-2025-62513 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, resulting in short-lived ACME verification challenge codes being leaked in the audit logs. Additionally, this impacts those using the OIDC issuer functionality of the identity subsystem, auth and token response codes along with claims could be leaked in the audit logs. ACME verification codes are not usable after verification or challenge expiry so are of limited long-term use. This issue has been patched in OpenBao 2.4.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbao | Openbao | >= 2.2.0, < 2.4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-62513?
How severe is CVE-2025-62513?
How do I fix CVE-2025-62513?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62508Citizen is a MediaWiki skin that makes extensions part of th…6.5
- CVE-2025-62509FileRise is a self-hosted web-based file manager with multi-…8.1
- CVE-2025-6251The Royal Elementor Addons and Templates plugin for WordPres…6.4
- CVE-2025-62510FileRise is a self-hosted web-based file manager with multi-…8.1
- CVE-2025-62511yt-grabber-tui is a C++ terminal user interface application …6.3
- CVE-2025-62512Piwigo is an open source photo gallery application for the w…5.3
- CVE-2025-62514Parsec is a cloud-based application for cryptographically se…7.1
- CVE-2025-62515pyquokka is a framework for making data lakes work for time …9.8
- CVE-2025-62516Rejected reason: Further research determined the issue is no…
- CVE-2025-62517Rollbar.js offers error tracking and logging from Javascript…5.9
- CVE-2025-62518astral-tokio-tar is a tar archive reading/writing library fo…8.1
- CVE-2025-62519phpMyFAQ is an open source FAQ web application. Prior to ver…7.2
Are you affected by CVE-2025-62513?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
