Количество 5
Количество 5
CVE-2025-6013
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
CVE-2025-6013
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
GHSA-7rx2-769v-hrwf
HashiCorp Vault ldap auth method may not have correctly enforced MFA
BDU:2025-09582
Уязвимость реализации протокола LDAP платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации
ROS-20250905-07
Множественные уязвимости vault
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-6013 Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2025-6013 Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-7rx2-769v-hrwf HashiCorp Vault ldap auth method may not have correctly enforced MFA | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
BDU:2025-09582 Уязвимость реализации протокола LDAP платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
ROS-20250905-07 Множественные уязвимости vault | CVSS3: 9.1 | 3 месяца назад |
Уязвимостей на страницу