CVE-2025-62705

Description

A flaw was found in OpenBao. The audit log does not properly redact sensitive fields when relevant subsystems return []byte response parameters instead of strings. This includes, but is not limited to, sys/raw with use of encoding=base64, causing all data to be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, causing the public keys to be emitted to the audit log.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Logging sensitive user data, full path names, or system information often provides attackers with an additional, less-protected path to acquiring the information.

Frequently Asked Questions

Want to get errata notifications? Sign up here.