PT-2025-32152 · Hashicorp+1 · Vault Enterprise+2
Yarden Porat
·
Published
2025-08-06
·
Updated
2026-05-24
·
CVE-2025-6013
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Vault versions prior to 1.20.2
Vault Enterprise versions prior to 1.20.2
Vault Enterprise version 1.19.8
Vault Enterprise version 1.18.13
Vault Enterprise version 1.16.24
Description
The LDAP authentication method in Vault and Vault Enterprise may not have correctly enforced multi-factor authentication (MFA) when
username as alias was set to true and a user had multiple Common Names (CNs) that were equal but contained leading or trailing spaces.Recommendations
Upgrade to Vault Community Edition version 1.20.2 or later.
Upgrade to Vault Enterprise version 1.20.2 or later.
Upgrade to Vault Enterprise version 1.19.8.
Upgrade to Vault Enterprise version 1.18.13.
Upgrade to Vault Enterprise version 1.16.24.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Vault
Vault Enterprise