Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
References
Link | Resource |
---|---|
https://discuss.hashicorp.com/t/hcsec-2025-17-vault-totp-secrets-engine-code-reuse/76036 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Aug 2025, 18:09
Type | Values Removed | Values Added |
---|---|---|
First Time |
Hashicorp vault
Hashicorp |
|
CPE | cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:vault:1.20.0:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* |
|
References | () https://discuss.hashicorp.com/t/hcsec-2025-17-vault-totp-secrets-engine-code-reuse/76036 - Vendor Advisory |
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Aug 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-01 18:15
Updated : 2025-08-13 18:09
NVD link : CVE-2025-6014
Mitre link : CVE-2025-6014
CVE.ORG link : CVE-2025-6014
JSON object : View
Products Affected
hashicorp
- vault
CWE
CWE-156
Improper Neutralization of Whitespace