CVE-2025-3879

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.19.0:*:*:*:enterprise:*:*:*

History

12 Aug 2025, 01:39

Type Values Removed Values Added
CPE cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:1.19.0:*:*:*:enterprise:*:*:*
References () https://discuss.hashicorp.com/t/hcsec-2025-07-vault-s-azure-authentication-method-bound-location-restriction-could-be-bypassed-on-login/74716 - () https://discuss.hashicorp.com/t/hcsec-2025-07-vault-s-azure-authentication-method-bound-location-restriction-could-be-bypassed-on-login/74716 - Vendor Advisory
First Time Hashicorp
Hashicorp vault

05 May 2025, 20:54

Type Values Removed Values Added
Summary
  • (es) El método de autenticación de Azure de Vault Community, Vault Enterprise ("Vault") no validaba correctamente las notificaciones en el token emitido por Azure, lo que podía provocar la omisión del parámetro bound_locations al iniciar sesión. Corregido en Vault Community Edition 1.19.1 y Vault Enterprise 1.19.1, 1.18.7, 1.17.14 y 1.16.18.

02 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 17:15

Updated : 2025-08-12 01:39


NVD link : CVE-2025-3879

Mitre link : CVE-2025-3879

CVE.ORG link : CVE-2025-3879


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-863

Incorrect Authorization