Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3879

Опубликовано: 02 мая 2025
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

EPSS

Процентиль: 17%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.6
redhat
4 месяца назад

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

CVSS3: 6.6
redos
около 2 месяцев назад

Уязвимость vault

CVSS3: 6.6
github
4 месяца назад

Hashicorp Vault Community vulnerable to Incorrect Authorization

EPSS

Процентиль: 17%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863