CVE-2025-6037
Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious certificate that could be used to impersonate another user. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
El método de autenticación de certificados TLS de Vault y Vault Enterprise («Vault») no validaba correctamente los certificados de cliente al configurarse con un certificado no perteneciente a una CA como [+certificado de confianza+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. En esta configuración, un atacante podría crear un certificado malicioso que podría usarse para suplantar la identidad de otro usuario. Corregido en Vault Community Edition 1.20.1 y Vault Enterprise 1.20.1, 1.19.7, 1.18.12 y 1.16.23.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-06-12 CVE Reserved
- 2025-08-01 CVE Published
- 2025-08-04 CVE Updated
- 2025-08-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
- CAPEC-122: Privilege Abuse
References (1)
URL | Tag | Source |
---|---|---|
https://discuss.hashicorp.com/t/hcsec-2025-18-vault-certificate-auth-method-did-not-validate-common-name-for-non-ca-certificates/76037 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
HashiCorp Search vendor "HashiCorp" | Vault Search vendor "HashiCorp" for product "Vault" | < 1.20.1 Search vendor "HashiCorp" for product "Vault" and version " < 1.20.1" | en |
Affected
| ||||||
HashiCorp Search vendor "HashiCorp" | Vault Enterprise Search vendor "HashiCorp" for product "Vault Enterprise" | < 1.20.1 Search vendor "HashiCorp" for product "Vault Enterprise" and version " < 1.20.1" | en |
Affected
|