Alexander Scheel
12 exploits
Active since Jul 2020
OpenBao's Namespace Deletion May Not Delete Data Properly
CVSS 7.5
OpenBao lacks user confirmation for OIDC direct callback mode
CVSS 9.6
Dogtagpki < 10.8.3 - Improper Certificate Validation
CVSS 6.8
OpenBao < 2.3.0 - Sensitive Information Exposure in Error Logs via Malformed Data Processing
CVSS 4.5
OpenBao < 2.3.0 - Unauthenticated Denial of Service via Rekey Operation Cancellation
CVSS 7.5
OpenBao 0.1.0-2.3.1 - User Lockout Bypass via User Entity Alias Attribution
CVSS 5.3
OpenBao 0.1.0-2.3.1 - Authenticated TOTP Code Reuse via Whitespace Neutralization
CVSS 6.5
OpenBao < 2.3.2 - MFA Bypass via LDAP Username Alias Without Normalization
CVSS 6.5
OpenBao < 2.3.2 - Login MFA Bypass via TOTP Whitespace Normalization
CVSS 5.7
OpenBao 2.2.0-2.4.1 - Sensitive Information Disclosure in Audit Logs
CVSS 7.5
OpenBao < 2.4.2 - Sensitive Information Disclosure in Audit Log
CVSS 4.9
OpenBao < 2.4.4 - Privilege Escalation via Identity Group Subsystem
CVSS 7.2