VYPR
Moderate severityNVD Advisory· Published May 2, 2025· Updated May 2, 2025

Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login

CVE-2025-3879

Description

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/vaultGo
>= 1.10.0, < 1.19.11.19.1

Affected products

2
  • Range: 0.10.0
  • HashiCorp/Vault Enterprisev5
    Range: 0.10.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.