openbao Vulnerabilities and Affected Products
Vulnerabilities associated with openbao-plugins.
Products
Clear product- openbao23 vulnerabilities
- openbao-plugins1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-59048HIGH | OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth MethodOpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS auth method. The vulnerability allows an IAM role from an untrusted AWS account to authenticate by impersonating a role with the same name in a trusted account, leading to unauthorized access. This impacts all users of the auth-aws plugin who operate in a multi-account AWS environment where IAM role names may not be u… | CVSS8.1v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |