User Lockout Bypass Vulnerability in OpenBao by OpenBao
CVE-2025-54998
5.3MEDIUM
What is CVE-2025-54998?
In OpenBao versions ranging from 0.1.0 to 2.3.1, a significant security flaw has been identified that allows attackers to bypass the automatic user lockout mechanisms specifically within the Userpass and LDAP authentication systems. This vulnerability arises due to inconsistencies in aliasing between the pre-flight and full login request user entity alias configurations. The issue has been addressed in version 2.3.2. To mitigate risks while users upgrade to the latest version, it is advisable to implement rate-limiting quotas on the affected authentication endpoints.
Affected Version(s)
openbao >= 0.1.0, < 2.3.2