User Enumeration Vulnerability in OpenBao Software Management Solution
CVE-2025-54999

3.7LOW

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
9 August 2025

What is CVE-2025-54999?

OpenBao, a software solution designed for the management, storage, and distribution of sensitive data, exhibits a user enumeration vulnerability in versions 0.1.0 through 2.3.1 when utilizing the userpass authentication method. This flaw allows malicious users to differentiate between valid and invalid usernames based on timing discrepancies in response. This leakage of information could potentially lead to unauthorized access attempts. OpenBao has addressed this issue in version 2.3.2, and users are advised to consider alternative authentication methods or to implement rate limiting to mitigate the risks associated with this vulnerability.

Affected Version(s)

openbao >= 0.1.0, < 2.3.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54999 : User Enumeration Vulnerability in OpenBao Software Management Solution