LDAP Authentication Flaw in HashiCorp Vault and Vault Enterprise
CVE-2025-6013
What is CVE-2025-6013?
The LDAP authentication method in Vault and Vault Enterprise may allow for an MFA enforcement bypass when the 'username_as_alias' feature is enabled. This issue arises particularly when user accounts contain multiple common names (CNs) that only differ by leading or trailing whitespace. As a result, users may not be prompted for multi-factor authentication as expected, potentially exposing sensitive resources. The issue has been addressed in recent updates to the respective versions of Vault.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vault 64 bit 1.10.0 < 1.20.2
Vault Enterprise 64 bit 1.10.0 < 1.20.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved