Authentication Method Flaw in Vault by HashiCorp
CVE-2025-3879
8.8HIGH
What is CVE-2025-3879?
In Vault by HashiCorp, an improper validation within the Azure authentication method may allow an attacker to bypass the bound_locations parameter during the login process. This flaw can lead to unauthorized access, as the system fails to enforce location restrictions effectively. The issue has been addressed in multiple versions, ensuring users migrate to the patched editions to maintain secure deployments.
Affected Version(s)
Vault 64 bit 0.10.0 < 1.19.1
Vault Enterprise 64 bit 0.10.0 < 1.19.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved