CVE-2025-3879

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
Configurations

No configuration.

History

05 May 2025, 20:54

Type Values Removed Values Added
Summary
  • (es) El método de autenticación de Azure de Vault Community, Vault Enterprise ("Vault") no validaba correctamente las notificaciones en el token emitido por Azure, lo que podía provocar la omisión del parámetro bound_locations al iniciar sesión. Corregido en Vault Community Edition 1.19.1 y Vault Enterprise 1.19.1, 1.18.7, 1.17.14 y 1.16.18.

02 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 17:15

Updated : 2025-05-05 20:54


NVD link : CVE-2025-3879

Mitre link : CVE-2025-3879

CVE.ORG link : CVE-2025-3879


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization