CVE-2025-3879 Details
Description
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
A vulnerability exists in the Azure authentication method of HashiCorp Vault (both Community and Enterprise editions) versions 0.10.0 prior to 1.19.0, as well as Vault Enterprise versions 1.18.6, 1.17.13, and 1.16.17. The issue arises because the authentication method did not properly validate claims in Azure-issued tokens, potentially allowing users to bypass geographical restrictions set by the bound_locations parameter during login. This could be exploited by manipulating login parameters to meet login requirements while circumventing location restrictions.
Users are advised to upgrade to Vault Community Edition 1.19.1 or Vault Enterprise versions 1.19.1, 1.18.7, 1.17.14, or 1.16.18. General upgrade guidance is available in the 'Upgrading Vault' documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2025-07-vault-s-azure-authentication-method-bound-location-restriction-could-be-bypassed-on-login/74716 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp vault | >= 0.10.0, < 1.16.18 >= 0.10.0, < 1.19.1 >= 1.17.0, < 1.17.14 >= 1.18.0, < 1.18.7 1.19.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | Initial Analysis | [email protected] |
| May 2, 2025 | New CVE Received | [email protected] |