CVE-2025-6013
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Vendor
Product
CWE
Yayın Tarihi
2025-08-06 10:15:35
Güncelleme
2025-12-15 16:13:23
Source Identifier
security@hashicorp.com
KEV Date Added
-