Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
(opens in new tab)
(csoonline.com)
29 points
GavCo
10mo ago
7 comments
Save
Share
7 comments
6 comments · 2 top-level
top
newest
oldest
milliams
10mo ago
· 4 in thread
Does this affect OpenBao as well?
JanMa
10mo ago
Yes this does affect OpenBao as well. We're actively working on getting a fix out as soon as possible
Scandiravian
10mo ago
Even more importantly; were these vulnerabilities responsibly disclosed to the OpenBao project before they were published?*
*Assuming OpenBao has a process in place for this
JanMa
10mo ago
This does affect OpenBao as well. We do have a process in place for responsible disclosure but unfortunately we were not informed about those issues before they were published.
1 more reply
chucky_z
10mo ago
Almost all of these except the enterprise MFA control group stuff will be in OpenBao yeah
yodon
10mo ago
Also discussed in
https://news.ycombinator.com/item?id=44821434
j
/
k
navigate · click thread line to collapse