{"schema_version":"1.9.0","id":"GHSA-2q8q-8fgw-9p6p","published":"2025-08-08T15:17:09Z","modified":"2026-07-27T09:11:18.365990511Z","aliases":["BIT-openbao-2025-55001","CVE-2025-55001","GO-2025-3859"],"summary":"OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias","details":"### Impact\n\nOpenBao allows assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When using the `username_as_alias=true` parameter in the LDAP auth method, the caller-supplied username is used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements.\n\n### Patches\n\nOpenBao v2.3.2 will patch this issue.\n\n### Workarounds\n\nLDAP methods are only vulnerable if using `username_as_alias=true`. Remove all usage of this parameter and update any entity aliases accordingly.\n\n### References\n\nThis issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:\n\n- https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092\n- https://nvd.nist.gov/vuln/detail/CVE-2025-6013","affected":[{"package":{"name":"github.com/openbao/openbao","ecosystem":"Go","purl":"pkg:golang/github.com/openbao/openbao"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"fixed":"2.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-2q8q-8fgw-9p6p/GHSA-2q8q-8fgw-9p6p.json"}},{"package":{"name":"github.com/openbao/openbao","ecosystem":"Go","purl":"pkg:golang/github.com/openbao/openbao"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250807212521-c52795c1ef74"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-2q8q-8fgw-9p6p/GHSA-2q8q-8fgw-9p6p.json"}}],"references":[{"type":"WEB","url":"https://github.com/openbao/openbao/security/advisories/GHSA-2q8q-8fgw-9p6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55001"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6013"},{"type":"WEB","url":"https://github.com/openbao/openbao/commit/c52795c1ef746c7f2c510f9225aa8ccbbd44f9fc"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092"},{"type":"PACKAGE","url":"https://github.com/openbao/openbao"}],"database_specific":{"cwe_ids":["CWE-156"],"github_reviewed":true,"github_reviewed_at":"2025-08-08T15:17:09Z","nvd_published_at":"2025-08-09T03:15:46Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}