Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4584 | Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0. |
Github GHSA |
GHSA-vxm9-8mfw-vc6g | Hermes improperly validates a JWT |
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp hermes |
|
| CPEs | cpe:2.3:a:hashicorp:hermes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hashicorp
Hashicorp hermes |
Thu, 20 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0. | |
| Title | HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-02-20T14:24:57.660Z
Reserved: 2025-02-13T23:43:25.448Z
Link: CVE-2025-1293
Updated: 2025-02-20T14:24:52.754Z
Status : Analyzed
Published: 2025-02-20T01:15:09.950
Modified: 2025-12-18T15:02:46.217
Link: CVE-2025-1293
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA