<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">openbao-2.4.3-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2025:16725</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-10-23T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-10-23T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-10-23T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">openbao-2.4.3-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the openbao-2.4.3-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2025-16725</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-62513/</URL>
      <Description>SUSE CVE CVE-2025-62513 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-62705/</URL>
      <Description>SUSE CVE CVE-2025-62705 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="openbao-2.4.3-1.1">
      <FullProductName ProductID="openbao-2.4.3-1.1">openbao-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-agent-2.4.3-1.1">
      <FullProductName ProductID="openbao-agent-2.4.3-1.1">openbao-agent-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-cassandra-database-plugin-2.4.3-1.1">
      <FullProductName ProductID="openbao-cassandra-database-plugin-2.4.3-1.1">openbao-cassandra-database-plugin-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-influxdb-database-plugin-2.4.3-1.1">
      <FullProductName ProductID="openbao-influxdb-database-plugin-2.4.3-1.1">openbao-influxdb-database-plugin-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-mysql-database-plugin-2.4.3-1.1">
      <FullProductName ProductID="openbao-mysql-database-plugin-2.4.3-1.1">openbao-mysql-database-plugin-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-mysql-legacy-database-plugin-2.4.3-1.1">
      <FullProductName ProductID="openbao-mysql-legacy-database-plugin-2.4.3-1.1">openbao-mysql-legacy-database-plugin-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-postgresql-database-plugin-2.4.3-1.1">
      <FullProductName ProductID="openbao-postgresql-database-plugin-2.4.3-1.1">openbao-postgresql-database-plugin-2.4.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openbao-server-2.4.3-1.1">
      <FullProductName ProductID="openbao-server-2.4.3-1.1">openbao-server-2.4.3-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="openbao-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-2.4.3-1.1">openbao-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-agent-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-agent-2.4.3-1.1">openbao-agent-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-cassandra-database-plugin-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-cassandra-database-plugin-2.4.3-1.1">openbao-cassandra-database-plugin-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-influxdb-database-plugin-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-influxdb-database-plugin-2.4.3-1.1">openbao-influxdb-database-plugin-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-mysql-database-plugin-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-mysql-database-plugin-2.4.3-1.1">openbao-mysql-database-plugin-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-mysql-legacy-database-plugin-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-mysql-legacy-database-plugin-2.4.3-1.1">openbao-mysql-legacy-database-plugin-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-postgresql-database-plugin-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-postgresql-database-plugin-2.4.3-1.1">openbao-postgresql-database-plugin-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openbao-server-2.4.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openbao-server-2.4.3-1.1">openbao-server-2.4.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, resulting in short-lived ACME verification challenge codes being leaked in the audit logs. Additionally, this impacts those using the OIDC issuer functionality of the identity subsystem, auth and token response codes along with claims could be leaked in the audit logs. ACME verification codes are not usable after verification or challenge expiry so are of limited long-term use. This issue has been patched in OpenBao 2.4.2.</Note>
    </Notes>
    <CVE>CVE-2025-62513</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:openbao-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-agent-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-cassandra-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-influxdb-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-mysql-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-mysql-legacy-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-postgresql-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-server-2.4.3-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-62513.html</URL>
        <Description>CVE-2025-62513</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1252506</URL>
        <Description>SUSE Bug 1252506</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.</Note>
    </Notes>
    <CVE>CVE-2025-62705</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:openbao-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-agent-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-cassandra-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-influxdb-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-mysql-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-mysql-legacy-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-postgresql-database-plugin-2.4.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openbao-server-2.4.3-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-62705.html</URL>
        <Description>CVE-2025-62705</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1252505</URL>
        <Description>SUSE Bug 1252505</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
