Authentication Method Flaw in Vault by HashiCorp
CVE-2025-3879

6.6MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
2 May 2025

What is CVE-2025-3879?

In Vault by HashiCorp, an improper validation within the Azure authentication method may allow an attacker to bypass the bound_locations parameter during the login process. This flaw can lead to unauthorized access, as the system fails to enforce location restrictions effectively. The issue has been addressed in multiple versions, ensuring users migrate to the patched editions to maintain secure deployments.

Affected Version(s)

Vault 64 bit 0.10.0 < 1.19.1

Vault Enterprise 64 bit 0.10.0 < 1.19.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3879 : Authentication Method Flaw in Vault by HashiCorp