CVE-2025-6013

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Configurations

No configuration.

History

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) Es posible que el método de autenticación LDAP de Vault y Vault Enterprise (Vault) no haya aplicado correctamente la MFA si `username_as_alias` se configuró como `true` y un usuario tenía varios CN iguales, pero con espacios al principio o al final. Corregido en Vault Community Edition 1.20.2 y Vault Enterprise 1.20.2, 1.19.8, 1.18.13 y 1.16.24.

06 Aug 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 10:15

Updated : 2025-08-06 20:23


NVD link : CVE-2025-6013

Mitre link : CVE-2025-6013

CVE.ORG link : CVE-2025-6013


JSON object : View

Products Affected

No product.

CWE
CWE-156

Improper Neutralization of Whitespace