CVE-2025-55001CWE-156

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

Medium · published August 9, 2025

CVSS v3.1
6.5
EPSS
0%
Percentile
12.5
In the wild
Unconfirmed
What it is

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When the username_as_alias=true parameter in the LDAP auth method was in use, the caller-supplied username was used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements. This issue was fixed in version 2.3.2. To work around this, remove all usage of the username_as_alias=true parameter and update any entity aliases accordingly.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00221 · 12.5th percentile
Weakness
CWE-156 · Improper Neutralization of Whitespace
Published
2025-08-09T02:01Z
EPSS history
Timeline
  • 09 AUG 02:01Z
    OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
    cvelistv5