The vendor explicitly states that these products are not affected by this CVE.
- All currently supported Red Hat products
- Summary
- A flaw was found in OpenBao, an open source identity-based secrets management system. OpenBao's namespaces are designed for multi-tenant separation. However, a user in one tenant could revoke or renew the lease and underlying credentials of another tenant. This is possible if the other tenant intentionally leaks lease identifiers, and the attacker utilizes legacy, undocumented `sys/revoke` and `sys/renew` endpoints, bypassing access control mechanisms.
- Remediation
- No remediation text is recorded.
