Listen to this Post
The CVE-2025-XXXXX vulnerability exists within the AWS authentication method of HashiCorp Vault. This method allows entities from AWS, such as IAM principals, to authenticate to Vault using their native AWS credentials. The flaw arises when an administrator configures a Vault role using the `bound_iam_principal_arn` parameter with a wildcard (“) or when the same IAM role name is used across different, untrusted AWS accounts. Under these conditions, the Vault’s validation logic can be misled. An attacker in control of an AWS account containing an IAM principal with an identical name could generate valid AWS-signed STS `GetCallerIdentity` requests. Vault, when verifying this request, would incorrectly match the role name from the attacker’s account against the broadly configured binding in the Vault role, thereby granting the attacker authentication and the associated Vault permissions intended for the legitimate principal in a different account.
Platform: HashiCorp Vault
Version: < 1.21.0
Vulnerability: Auth Bypass
Severity: High
date: 2024-10-23
Prediction: Patch 2024-10-30
What Undercode Say:
aws sts get-caller-identity vault write auth/aws/login role=my-role pkcs7=$(curl -s http://169.254.169.254/latest/dynamic/instance-identity/pkcs7 | tr -d '\n') vault auth list
import boto3
client = boto3.client('sts')
response = client.get_caller_identity()
print(response['Arn'])
How Exploit:
1. Attacker controls separate AWS account.
2. Creates IAM role matching target name.
3. Assumes role, gets temporary credentials.
4. Uses credentials to call Vault AWS login.
5. Vault incorrectly validates principal ARN.
6. Attacker gains unauthorized Vault token.
Protection from this CVE
- Upgrade Vault to 1.21.0.
- Apply patches for 1.20.5/1.19.11/1.16.27.
- Avoid wildcards in
bound_iam_principal_arn. - Use full, unique principal ARNs for binding.
- Review and modify existing Vault roles.
Impact:
- Unauthorized Vault access.
- Privilege escalation.
- Secret data compromise.
- Full tenant compromise possible.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

