CVE-2025-3879
MEDIUM6.6EPSS 0.23%Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login
Published: 5/2/2025Modified: 8/13/2025
Description
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
Affected packages (3)
- Bitnami/vault>= 0.10.0, < 1.19.1
- Go/github.com/hashicorp/vault>= 1.10.0, < 1.19.1
- Go/github.com/hashicorp/vault>= 1.10.0, < 1.19.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.6 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
References (5)
- ADVISORYhttps://github.com/advisories/GHSA-f9ch-h8j7-8jwg
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-3879
- PATCHhttps://github.com/hashicorp/vault
- WEBhttps://discuss.hashicorp.com/t/hcsec-2025-07-vault-s-azure-authentication-method-bound-location-restriction-could-be-bypassed-on-login/74716
- WEBhttps://pkg.go.dev/vuln/GO-2025-3662