Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp terraform Provider |
|
| Vendors & Products |
Hashicorp
Hashicorp terraform Provider |
Fri, 21 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0. | |
| Title | Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method | |
| Weaknesses | CWE-1188 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published: 2025-11-21T15:02:27.081Z
Updated: 2025-11-24T18:00:33.469Z
Reserved: 2025-11-18T15:38:23.306Z
Link: CVE-2025-13357
Updated: 2025-11-21T15:30:54.628Z
Status : Awaiting Analysis
Published: 2025-11-21T15:15:51.313
Modified: 2025-11-25T22:16:42.557
Link: CVE-2025-13357
No data.