Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:terraform_provider:*:*:*:*:*:vault:*:* |
Mon, 24 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp terraform Provider |
|
| Vendors & Products |
Hashicorp
Hashicorp terraform Provider |
Fri, 21 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0. | |
| Title | Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method | |
| Weaknesses | CWE-1188 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published: 2025-11-21T15:02:27.081Z
Updated: 2025-11-24T18:00:33.469Z
Reserved: 2025-11-18T15:38:23.306Z
Link: CVE-2025-13357
Updated: 2025-11-21T15:30:54.628Z
Status : Analyzed
Published: 2025-11-21T15:15:51.313
Modified: 2025-12-10T21:00:48.097
Link: CVE-2025-13357
No data.