CVE-2025-3879: Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the boundlocations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3879?
CVE-2025-3879 is classified as a critical vulnerability due to its potential to bypass authentication restrictions in Azure Auth method.
How do I fix CVE-2025-3879?
To fix CVE-2025-3879, upgrade to Vault Community Edition 1.19.1 or Vault Enterprise 1.19.1, 1.18.7.
What products are affected by CVE-2025-3879?
CVE-2025-3879 affects HashiCorp Vault Community Edition and Vault Enterprise versions up to 1.19.1.
What is the impact of CVE-2025-3879?
The impact of CVE-2025-3879 could allow unauthorized users to bypass location restrictions during login.
When was CVE-2025-3879 disclosed?
CVE-2025-3879 was disclosed in 2025, highlighting a vulnerability in the Azure authentication method.