Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
1–9 of 9 posts
Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#2Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#3Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#4Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#5Does this affect OpenBao as well?
Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#6Does this affect OpenBao as well?
*Assuming OpenBao has a process in place for this
Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#7Does this affect OpenBao as well?
Even more importantly; were these vulnerabilities responsibly disclosed to the OpenBao project before they were published?* *Assuming OpenBao has a process in place for this
Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#8Does this affect OpenBao as well?
Re: Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur
#9Earlier quoted context omitted.
Even more importantly; were these vulnerabilities responsibly disclosed to the OpenBao project before they were published?* *Assuming OpenBao has a process in place for this
This does affect OpenBao as well. We do have a process in place for responsible disclosure but unfortunately we were not informed about those issues before they were published.
I'm very disappointed to hear that the researchers didn't do their due diligence and informed the OpenBao project about this issue before publishing
I imagine this is a stressful situation for everyone involved in the project, so I hope the researchers will do some reflections on how they can avoid this situation happening in the future