Skip to content
VaultGHSA-7rx2-769v-hrwf

HashiCorp Vault ldap auth method may not have correctly enforced MFA

Medium6.5CVE-2025-6013 · Published Aug 6, 2025 · updated Sep 10, 2026

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.20.21.20.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-156
Also known as
BIT-vault-2025-6013, CVE-2025-6013, GO-2025-3848

More Vault advisories

All Vault
Advisory
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Medium6.8Aug 1, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High7.2Aug 1, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Critical9.1Aug 1, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low3.7Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Medium6.5Aug 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.