ControlPlane and the OpenBao community recently patched a full exploit chain from unauthenticated access to full remote code execution that also affects IBM's HashiCorp Vault.

5 points•cipherboy•1 day ago•1 comment•

1 comment

variety86751 day ago
> As too many vulnerabilities have been unilaterally disclosed by HashiCorp–including last year’s RCE–the OpenBao maintainers declined to continue proactively disclosing and coordinating vulnerabilities with HashiCorp, despite initially doing this.

You'd never guess Red Hat and HashiCorp are owned by the same company

Read the full thread on Hacker News →

Related stories