CVE-2025-1293

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hashicorp:hermes:*:*:*:*:*:*:*:*

History

18 Dec 2025, 15:02

Type Values Removed Values Added
CPE cpe:2.3:a:hashicorp:hermes:*:*:*:*:*:*:*:*
Summary
  • (es) Las versiones de Hermes de hasta 0.4.0 validaron incorrectamente el JWT proporcionado cuando se usa el modo de autenticación AWS Alb, lo que puede permitir el bypass de autenticación. Esta vulnerabilidad, CVE-2025-1293, se fijó en Hermes 0.5.0.
First Time Hashicorp
Hashicorp hermes
References () https://discuss.hashicorp.com/t/hcsec-2025-03-hashicorp-hermes-improperly-validates-aws-alb-jwts-which-may-lead-to-authentication-bypass/73371 - () https://discuss.hashicorp.com/t/hcsec-2025-03-hashicorp-hermes-improperly-validates-aws-alb-jwts-which-may-lead-to-authentication-bypass/73371 - Vendor Advisory

20 Feb 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-20 01:15

Updated : 2025-12-18 15:02


NVD link : CVE-2025-1293

Mitre link : CVE-2025-1293

CVE.ORG link : CVE-2025-1293


JSON object : View

Products Affected

hashicorp

  • hermes
CWE
CWE-1390

Weak Authentication