Description
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2017 | HashiCorp Vault's revocation list not respected |
Github GHSA |
GHSA-9mh8-9j64-443f | HashiCorp Vault's revocation list not respected |
References
History
Thu, 15 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-15T14:59:25.849Z
Reserved: 2022-09-23T00:00:00.000Z
Link: CVE-2022-41316
Updated: 2024-08-03T12:42:44.924Z
Status : Modified
Published: 2022-10-12T21:15:09.857
Modified: 2025-05-15T15:16:03.330
Link: CVE-2022-41316
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA