CVE-2025-6013
MEDIUMDescription
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Is your site exposed to CVE-2025-6013?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
References
Frequently Asked Questions
What is CVE-2025-6013? +
How severe is CVE-2025-6013? +
What products are affected by CVE-2025-6013? +
How do I check if I'm vulnerable to CVE-2025-6013? +
Related Vulnerabilities
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. …
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new …
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect …
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying …