Authentication Method Flaw in Vault by HashiCorp
CVE-2025-3879
6.6MEDIUM
What is CVE-2025-3879?
In Vault by HashiCorp, an improper validation within the Azure authentication method may allow an attacker to bypass the bound_locations parameter during the login process. This flaw can lead to unauthorized access, as the system fails to enforce location restrictions effectively. The issue has been addressed in multiple versions, ensuring users migrate to the patched editions to maintain secure deployments.
Affected Version(s)
Vault 64 bit 0.10.0 < 1.19.1
Vault Enterprise 64 bit 0.10.0 < 1.19.1