Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41316


HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.


Published

2022-10-12T21:15:09.857

Last Modified

2025-05-15T15:16:03.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-295
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp vault < 1.9.10 Yes
Application hashicorp vault < 1.9.10 Yes
Application hashicorp vault < 1.10.7 Yes
Application hashicorp vault < 1.10.7 Yes
Application hashicorp vault < 1.11.4 Yes
Application hashicorp vault < 1.11.4 Yes

References