Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious certificate that could be used to impersonate another user. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.20.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.20.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6037.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.23"
}
]
},
{
"events": [
{
"introduced": "1.17.0"
},
{
"fixed": "1.18.12"
}
]
},
{
"events": [
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.7"
}
]
}
]