Realistic RCE Exploit Chain in OpenBao and Vault

3 pointsposted 4 hours ago
by cipherboy

1 Comments

variety8675

4 hours ago

> As too many vulnerabilities have been unilaterally disclosed by HashiCorp–including last year’s RCE–the OpenBao maintainers declined to continue proactively disclosing and coordinating vulnerabilities with HashiCorp, despite initially doing this.

You'd never guess Red Hat and HashiCorp are owned by the same company