9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Basic Information
ID
CVE-2025-6000
Source
HashiCorp
Published
Aug 1, 2025 at 17:40
Modified
Aug 1, 2025 at 18:12
Affected Product
Vendor
HashiCorp
Product
Vault
Version
0.8.0
Affected Versions
HashiCorp Vault 0.8.0
HashiCorp Vault Enterprise 0.8.0
HashiCorp Vault Enterprise 0.8.0