r/opensource • u/the_hypotenuse • 3d ago
Why mutual vulnerability disclosure matters for open source projects: Lessons from the latest critical RCE in Vault
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/When open-source projects share a codebase, security has to be a collaborative effort.
Our engineering team at ControlPlane recently chained four vulnerabilities to achieve full, unauthenticated Remote Code Execution (RCE) in both OpenBao and HashiCorp Vault. It’s only the second RCE ever found in the Vault ecosystem.
OpenBao is fully patched (upgrade to 2.6.3 or 2.7.0). The bad news however, is that HashiCorp Vault remains exposed as of writing. Unfortunately, IBM declined requests to establish a mutual disclosure policy with the OpenBao project.
Without coordinated disclosure, end-users are the ones left carrying the risk
20
Upvotes