HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-15T14:59:25.849Z
Reserved: 2022-09-23T00:00:00.000Z
Link: CVE-2022-41316

Updated: 2024-08-03T12:42:44.924Z

Status : Modified
Published: 2022-10-12T21:15:09.857
Modified: 2025-05-15T15:16:03.330
Link: CVE-2022-41316
