PT-2025-47785 · Hashicorp · Vault Terraform Provider

Published

2025-11-21

·

Updated

2025-11-25

·

CVE-2025-13357

CVSS v3.1
7.4
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vault Terraform Provider versions prior to 5.5.0
Description The Vault Terraform Provider was configured with an insecure default setting for the LDAP auth method. Specifically, the
deny null bind
parameter defaulted to false, which could allow authentication bypass if the LDAP server permitted anonymous or unauthenticated binds. This could potentially lead to unauthorized access.
Recommendations Update to Vault Terraform Provider version 5.5.0 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13357
GHSA-GMM6-J2G5-R52M
GO-2025-4152

Affected Products

Vault Terraform Provider