Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • 3 Votes
    6 Posts
    456 Views
    L
    Security update: 1.0.3 (OpenBao 2.6.3). Please update. OpenBao published nine advisories on 23 September, fixed in 2.6.3 and 2.7.0. This package ships the 2.6.3 patch release, so there are no new features, only the fixes. The most serious is a CRITICAL remote code execution in which a raft snapshot restore replaces the plugin catalog (GHSA-j6wc-jpvg-xfxq). This package uses raft storage, so it applies here, although it needs a highly privileged token to exploit. Also fixed are three HIGH issues: an ACL bypass via non-canonical URLs, a cross-namespace policy cache flaw, and unvalidated SANs through PKI ACME. There are also an open redirect in the OIDC provider UI and four low-severity issues. The update also moves the package to Cloudron base 5.1.0. Before publishing, it was tested as an update over real secrets, including a restore into an empty store and an OIDC sign-in, and it's already running in production. Some scanners will still list a few old OpenBao CVEs against the bao binary. Those are false positives: the release binary reports its Go module version as v0.0.0-…. Upstream is fixing that in 2.7 (openbao/openbao#3184). We love Bao and will do our best to keep this package well maintained.