External risk intelligence

Vault Terraform Provider LDAP Auth Method Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-13357

The vulnerability affects a Terraform provider used by administrators to manage infrastructure-as-code configurations. Terraform providers are typically used in isolated developer or CI/CD environments to interact with Vault rather than being directly internet-facing services. While it involves LDAP authentication configuration, the deployment context is internal automation and management rather than a public-facing network edge.

Authentication Bypass

Hashicorp Terraform Provider

4.2.0 to before 5.5.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security issue in HashiCorp's Terraform Provider for Vault, where an incorrect default setting for LDAP authentication could allow unauthorized access if the connected LDAP server permits anonymous binds. This misconfiguration, if exploited, could lead to authentication bypass and compromise system security.

  • Insecure default for authentication.
  • High-impact authentication bypass risk.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by leveraging an improperly configured LDAP authentication method within Vault's Terraform Provider. If the provider defaults to an insecure setting that allows unauthenticated binds to the underlying LDAP server, an attacker could bypass authentication and gain unauthorized access. This could potentially lead to full system compromise if the attacker can then leverage the elevated access.

  • No authentication required for entry.
  • Weak LDAP bind defaults.
  • Authentication bypass and system compromise.

Live Threat

Current exploitation, exposure, and threat context

When configured with an LDAP server that permits anonymous or unauthenticated binds, this vulnerability could allow unauthorized access to Vault, bypassing authentication controls. This could expose sensitive information managed by Vault and allow for unauthorized modification of its configuration.

  • Sensitive Vault data and configuration.
  • Authentication bypass via unauthenticated LDAP binds.
  • Unauthorized access and configuration changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The HashiCorp Terraform provider for Vault is likely managed by infrastructure or platform teams responsible for IaC and Vault configurations. The first step is to identify all instances of the affected Terraform provider, determine if they are used to configure environments with external LDAP binds, and locate the team accountable for those configurations. Planning remediation should be risk-based, considering the potential for authentication bypass via insecure LDAP binds.

  • Infrastructure/Platform teams own the issue.
  • Verify LDAP bind configurations; confirm exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the HashiCorp Vault Terraform Provider?

It is a software tool that allows engineers to manage HashiCorp Vault configurations using Infrastructure as Code (IaC). By using Terraform to define Vault settings, teams can automate the deployment of security policies, auth methods, and secrets engines across their environments.

What does CVE-2025-13357 mean?

This CVE identifies a security weakness classified as CWE-1188, which involves the use of insecure default settings. In this case, the Terraform provider incorrectly set the 'deny_null_bind' parameter to false by default for LDAP authentication. This mistake can fail to block unauthenticated or anonymous requests, creating a pathway for an unauthorized party to bypass authentication.

When does this vulnerability trigger?

The vulnerability triggers when the Vault Terraform Provider manages an LDAP auth method connected to an LDAP server that happens to permit anonymous or unauthenticated binds. If your LDAP server requires valid credentials for every bind, or if you have explicitly configured the settings to override the default, the specific mechanism for this bypass is not present.

Is this vulnerability likely to be internet-facing?

According to Halo Surface Signal, it is unlikely. Terraform providers generally operate within isolated developer or CI/CD environments rather than on the public-facing network edge. Because these tools are used for internal automation and infrastructure management, they are typically shielded from direct internet exposure.

How do I address this security risk?

Your first step is to locate all instances where the affected Vault Terraform Provider is in use. Once identified, work with the team managing those infrastructure configurations to verify your LDAP bind settings and upgrade the provider to version 5.5.0 or later to ensure the secure default is applied correctly.

References