CRITICAL🇵🇱 Wersja polska

CVE-2025-6000

CVSS 9.1v3.1pub. 2025-08-01upd. 2025-08-13

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

🤖 AI Analysis
How it works

The attack requires possession of an operator account in the main namespace (root namespace) with write permissions to the sys/audit endpoint. If a plugin directory is configured in the Vault configuration, an attacker can through an appropriately crafted request to sys/audit cause arbitrary code execution at the operating system host level. The vulnerability mechanism is classified as code injection (CWE-94), which means the ability to inject and execute malicious code.

Impact

An attacker can obtain arbitrary code execution on the host with Vault process permissions, which in practice means complete takeover of the server, the ability to exfiltrate secrets, and further lateral movement in the infrastructure.

Mitigation & patch

You should update to Vault Community Edition version 1.20.1 or correspondingly Vault Enterprise 1.20.1, 1.19.7, 1.18.12 or 1.16.23. Additionally, as a temporary measure, it is advisable to verify and limit the number of accounts with write permissions to sys/audit in the root namespace and consider removing the plugin directory configuration if it is not required.

Who is affected

HashiCorp Vault Community Edition and Vault Enterprise — all versions before 1.20.1 (Community Edition), as well as Enterprise in versions before 1.20.1, 1.19.7, 1.18.12 and 1.16.23, provided that a plugin directory is configured in the configuration.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Hashicorp Vault

    APP
    Hashicorp
    1.20.00.8.0 – 1.16.23 (excl.)0.8.0 – 1.20.1 (excl.)1.17.0 – 1.18.12 (excl.)1.19.0 – 1.19.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-40186CRITICAL9.1PL ✓same product

HashiCorp Vault: błędne nadpisywanie metadanych aliasów encji

CVE-2022-36129CRITICAL9.1PL ✓same product

HashiCorp Vault Enterprise — nieuwierzytelniony endpoint umożliwia manipulację węzłami HA

CVE-2020-35192CRITICAL9.8PL ✓same product

Puste hasło root w oficjalnych obrazach Docker HashiCorp Vault

CVE-2020-12757CRITICAL9.8PL ✓same product

HashiCorp Vault: nieprawidłowy czas ważności poświadczeń GCP

CVE-2020-10661CRITICAL9.1PL ✓same product

HashiCorp Vault: błędne dziedziczenie uprawnień dla nowych Namespaces