HashiCorp Vault RCE Flaw Persists as OpenBao Ships Patches
Researchers disclosed a critical RCE vulnerability in HashiCorp Vault and OpenBao that lets an unauthenticated attacker fully compromise a server by chaining four flaws. OpenBao has patched versions 2.6.3 and 2.7.0, while HashiCorp Vault remains exposed due to uncoordinated disclosure between IBM and HashiCorp.
- Exploitation needs only unauthenticated access and a configured Raft snapshot policy
- OpenBao fixed the flaw in versions 2.6.3 and 2.7.0
- HashiCorp Vault has no official patch due to disclosure delays
- Temporary mitigations: network segmentation and runtime protection
Read next
Security