ControlPlane and the OpenBao community recently patched a full exploit chain from unauthenticated access to full remote code execution that also affects IBM's HashiCorp Vault.
1 comment
variety86751 day ago
> As too many vulnerabilities have been unilaterally disclosed by HashiCorp–including last year’s RCE–the OpenBao maintainers declined to continue proactively disclosing and coordinating vulnerabilities with HashiCorp, despite initially doing this.
You'd never guess Red Hat and HashiCorp are owned by the same company
Read the full thread on Hacker News →
Related stories
- Ars Technica · 0 points · 11 days ago
- PS5 Relapse Exploitgithub.comHacker News · 345 points · 1 day ago
- Anthropic is a supply chain risk for all of usbuilding138.comHacker News · 1 points · 3 days ago
- Hacker News · 2 points · 10 days ago
- Hacker News · 1 points · 9 days ago
- Hacker News · 6 points · 11 days ago