OpenBaoGHSA-jg74-mwgw-v6x3
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
High7.5CVE-2024-7594 · Published Sep 26, 2024 · updated Sep 10, 2026
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | >= 0.1.0 | No fix yet |
| < 0.0.0-20241003222810-d5b4e9224698 | 0.0.0-20241003222810-d5b4e9224698 | |
| github.com/hashicorp/vault Go | >= 1.7.7, < 1.17.6 | 1.17.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-732
- Also known as
- BIT-openbao-2024-7594, BIT-vault-2024-7594, CVE-2024-7594, GO-2024-3162
- nvd.nist.gov/vuln/detail/CVE-2024-7594
- github.com/openbao/openbao/pull/561
- github.com/openbao/openbao/commit/d5b4e922469830ac335b21dc0e8f9878c501a884
- discuss.hashicorp.com/t/hcsec-2024-20-vault-ssh-secrets-engine-configuration-did-not-restrict-valid-principals-by-default/70251
- github.com/hashicorp/vault
- openbao.org/docs/release-notes/2-0-0/#202
- pkg.go.dev/vuln/GO-2024-3162
- security.netapp.com/advisory/ntap-20250110-0007
More OpenBao advisories
All OpenBao| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 82025 | OpenBao TOTP Secrets Engine Code Reuse | Medium6.5 | 0.0.0-20250806193153-183891f8d535+1 more |
| Aug 82025 | OpenBao has a Timing Side-Channel in the Userpass Auth Method | Low3.7 | 0.0.0-20250806193356-4d9b5d3d6486+1 more |
| Aug 82025 | OpenBao Userpass and LDAP User Lockout Bypass | Medium5.3 | 0.0.0-20250807212521-c52795c1ef74+1 more |
| Aug 82025 | Privileged OpenBao Operator May Execute Code on the Underlying Host | Critical9.1 | 0.0.0-20250806194004-a14053c9679d+1 more |
| Aug 82025 | OpenBao Root Namespace Operator May Elevate Token Privileges | High7.2 | 0.0.0-20250806193240-9b0b5d4f345f+1 more |
| Jun 262025 | OpenBao allows cancellation of root rekey and recovery rekey operations without authentication | Medium | 0.0.0-20250625150133-fe75468822a2 |