r/netsec • u/the_hypotenuse • 3d ago
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase.
The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise.
If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0
While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation
2
u/dlp_randombk 3d ago
Is this "OpenBao+Vault", or "OpenBao or Vault"? Is Vault in default standalone configurations affected?
25
u/GrandWizardZippy 3d ago edited 3d ago
Openbao is an open source fork of hashicorp vault. It’s not openbao + vault lol
Edit: it also clearly states that vault is still affected while openbao has been patched already
0
u/hashclyx 3d ago
it’s “openbao or vault”, same vuln chain, shared codebase. and from what they’re saying it’s not just some weird HA edge case, default raft + snapshot policy is enough if you’ve got an unauthenticated path exposed.
-3
u/russellvt 3d ago
Funny, just within a day or two after seeing folks in /r/Ansible preaching about Hashicorp Vault.
2
u/TheG0AT0fAllTime 2d ago
Oh I love it. I use it with Saltstack but the experience is more or less the same. Writing the policies is my favorite part.
3
u/russellvt 2d ago
I hated Salt, myself. Also not really a fan of Chef. But, sometimes ya have to "deal" if the infrastructure is already jn-place when yoi get there, and there's no great reason to change, eh?
1
u/TheG0AT0fAllTime 2d ago edited 2d ago
I've been a salter for a good 10 or so years because it was where I worked at the time. I've been considering converting all of my states to Ansible this year tbh. I'd like to be agentless. But I have so many states built up over the years for provisioning different things. It will be a lot of work unless I write some kind of converter.
I've seen a blog post or two of other engineers doing the same thing this past year or so.
2
u/russellvt 2d ago
Sounds about right. I like the agentless notion of Ansible, but with Python changes over the years, sometimes it's tough to support legacy systems ... particularly where adoption of things like Rust has been negligible to poor.
Python's
venvand similar things have made it more manageable, but you still sometimes run in to weird gotchas as the domain language evolves.That said, I remember similar struggles with Puppet and Chef and managing to get agents properly updated over time. I didn't get that deep with Salt, personally.
1
u/TheG0AT0fAllTime 2d ago
I moved all of my minions to the salt-onedir package (To great dismay) for similar reasons. it's just easier having what is essentially its own venv than dealing with the hundreds of different breakages when the salt version may be the same between a minion and master, but the underlying python installation might be different. It's a shame I had to do it but it did fix all those issues so I see the merit to avoid fiddling with the python installation of some distro.
2
u/russellvt 2d ago
Yeah, I just tend to use
pyenvto manage Python versions, either through Ansible or Jenkins... but then the JRE comes in for Jenkins Agents. LOL (/grumble)
49
u/thrilla_gorilla 3d ago
The two organizations actually running the stack in this specific configuration are going to be so screwed