Identity-based Secrets Management Vulnerability in OpenBao System
CVE-2025-62513
What is CVE-2025-62513?
OpenBao, an open-source identity-based secrets management solution, suffers from a vulnerability in its audit log across versions 2.2.0 to 2.4.1. The error lies in a regression that fails to properly redact raw HTTP bodies for certain endpoints. As a result, sensitive information such as ACME verification challenge codes and OIDC token response details could inadvertently be exposed in the audit logs, compromising confidentiality. Though ACME verification codes have limited usability post-expiry, their exposure represents a potential risk to users. The issue has been rectified in OpenBao version 2.4.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openbao >= 2.2.0, < 2.4.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
