1 results (0.002 seconds)

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

20 Feb 2025 — Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0. • https://discuss.hashicorp.com/t/hcsec-2025-03-hashicorp-hermes-improperly-validates-aws-alb-jwts-which-may-lead-to-authentication-bypass/73371 • CWE-1390: Weak Authentication •