OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacted the following subsystems:
Third-party plugins may be affected.
OpenBao v2.4.2 will patch this issue.
If users do not use the above functionality, they are not impacted. ACME verification codes are not usable after verification or challenge expiry so are of limited long-term use.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-532"
],
"github_reviewed_at": "2025-10-22T19:37:53Z",
"nvd_published_at": "2025-10-22T20:15:38Z",
"github_reviewed": true
}