Логотип exploitDog
bind:CVE-2025-13357
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13357

Количество 2

Количество 2

nvd логотип

CVE-2025-13357

3 месяца назад

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-gmm6-j2g5-r52m

3 месяца назад

Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13357

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.

CVSS3: 7.4
0%
Низкий
3 месяца назад
github логотип
GHSA-gmm6-j2g5-r52m

Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default

CVSS3: 7.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу