CVE-2025-6014
MEDIUMDescription
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Is your site exposed to CVE-2025-6014?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
| hashicorp | vault |
References
Frequently Asked Questions
What is CVE-2025-6014? +
How severe is CVE-2025-6014? +
What products are affected by CVE-2025-6014? +
How do I check if I'm vulnerable to CVE-2025-6014? +
Related Vulnerabilities
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true …
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new …
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect …
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying …