CVE-2025-1293
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
Vendor
Product
CWE
Yayın Tarihi
2025-02-20 01:15:09
Güncelleme
2025-12-18 15:02:46
Source Identifier
security@hashicorp.com
KEV Date Added
-