Sploitus

CVE-2025-6013

No indexed exploits for CVE-2025-6013 yet

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.

Affected products
Red Os, Vault, Vault Enterprise
Hashicorp Vault
≤ 1.15.16, 1.20.2, 1.16.24, 1.18.13, 1.19.8
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
0.5% (40th percentile)
Weakness
CWE-156
NVD status
Analyzed
Published
2025-08-06
Attack patterns
CAPEC-180
CVE-2025-6013 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-6013 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-6013 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.