First published: Thu Feb 20 2025(Updated: )
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
Credit: security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Hermes | <0.5.0 | |
go/github.com/hashicorp-forge/hermes | <0.5.0 | 0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1293 is considered a medium severity vulnerability due to its potential for authentication bypass.
To fix CVE-2025-1293, upgrade Hermes to version 0.5.0 or later.
CVE-2025-1293 affects Hermes versions up to and including 0.4.0.
CVE-2025-1293 is an authentication bypass vulnerability related to improper JWT validation.
CVE-2025-1293 impacts the security of AWS ALB authentication when used with Hermes, allowing unauthorized access.