|
|
|
|
|
by cipherboy
315 days ago
|
|
I do not speak for HashiCorp, but they have published information on this CVE here: https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enu... OpenBao is reasonably confident in our fix: https://github.com/openbao/openbao/pull/1628 We had earlier pulled support for pre-Vault-1.0 userpass pre-bcrypt hashing (so there's no longer a timing difference there that could be used for enumeration) and using cache busting on lookup should also ensure consistency across storage layers. Plus, normalizing the remaining error messages through when the user's credential is fully validated as correct. |
|
why does this phrase not fill me with confidence?