Trail of Bits reposted this
Critical RCE chain across Vault and OpenBao patched for the latter, great work from the team operationalizing and remediating. Thanks to Trail of Bits for the collaboration and Alexander Scheel for PoC, coordinating and delivering fixes, and detail of IBM's response to our efforts to disclose Vault vulns in the post.
In collaboration with the OpenBao community, ControlPlane has recently helped remediate a full exploit chain that allowed unauthenticated access and escalation to full Remote Code Execution (RCE). This marks only the second-ever RCE vulnerability discovered in Vault and OpenBao, combining disclosures from three independent reporters into a single, devastating exploit chain. How the chain works: By abusing a PKI ACME validation bypass, an unauthenticated attacker can spoof a service provisioner's identity. Then, they can modify an admin account, escalate privileges across namespaces, and ultimately achieve full RCE by restoring a malicious Raft storage snapshot. We've published a full technical breakdown. Link to the blog is in the comments, or get involved in the conversation on Hacker News #CyberSecurity #OpenBao #VulnerabilityManagement #InfoSec #CloudNativeSecurity