vault: insufficient certificate revocation list checking
Published Oct 12, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.43%
Description
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Affected products
No data.
No data.
RHODF-4.13-RHEL-9
odf4/mcg-rhel9-operator:v4.13.0-41
Fixed · RHSA-2023:3742
RHODF-4.13-RHEL-9
odf4/rook-ceph-rhel9-operator:v4.13.0-70
Fixed · RHSA-2023:3742
Red Hat OpenShift Container Platform 4.12
openshift4/ose-installer:v4.12.0-202301090455.p0.gba94031.assembly.stream
Fixed · RHSA-2022:7399
Red Hat OpenShift Container Platform 4.13
openshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream
Fixed · RHSA-2023:1326
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/cluster-curator-controller-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/managedcluster-import-controller-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/topology-aware-lifecycle-manager-rhel8-operator
Affected
Red Hat Openshift Container Storage 4
ocs4/cephcsi-rhel8
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/mcg-rhel8-operator
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/ocs-rhel8-operator
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/rook-ceph-rhel8-operator
Out of support scope
Red Hat Openshift Data Foundation 4
ocs4/mcg-rhel8-operator
Affected
Red Hat Openshift Data Foundation 4
odf4/cephcsi-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/ocs-rhel9-operator
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-rhel9-operator
Will not fix
Red Hat Openshift Data Foundation 4
odf4/odf-rhel9-operator
Affected
Red Hat Openshift Data Foundation 4
odf4/odr-rhel9-operator
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHODF-4.13-RHEL-9 | odf4/mcg-rhel9-operator:v4.13.0-41 | Fixed | RHSA-2023:3742 |
| RHODF-4.13-RHEL-9 | odf4/rook-ceph-rhel9-operator:v4.13.0-70 | Fixed | RHSA-2023:3742 |
| Red Hat OpenShift Container Platform 4.12 | openshift4/ose-installer:v4.12.0-202301090455.p0.gba94031.assembly.stream | Fixed | RHSA-2022:7399 |
| Red Hat OpenShift Container Platform 4.13 | openshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream | Fixed | RHSA-2023:1326 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/cluster-curator-controller-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/managedcluster-import-controller-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/topology-aware-lifecycle-manager-rhel8-operator | Affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | ocs4/mcg-rhel8-operator | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-rhel9-operator | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Will not fix | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-rhel9-operator | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odr-rhel9-operator | Will not fix | n/a |
github.com/hashicorp/vault
Go
Introduced 0 Fixed 1.9.10github.com/hashicorp/vault
Go
Introduced 1.11.0 Fixed 1.11.4github.com/hashicorp/vault
Go
Introduced 1.10.0 Fixed 1.10.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/vault | 0 | 1.9.10 |
| Go | github.com/hashicorp/vault | 1.11.0 | 1.11.4 |
| Go | github.com/hashicorp/vault | 1.10.0 | 1.10.7 |
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-41316 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2135339 Issue Tracking
- https://discuss.hashicorp.com Vendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2022-24-vaults-tls-cert-auth-method-only-loaded-crl-after-first-request/45483 Vendor Advisory
- https://github.com/advisories/GHSA-9mh8-9j64-443f Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41316
- https://security.netapp.com/advisory/ntap-20221201-0001 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41316
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-41316 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2135339 | Issue Tracking | |
| https://discuss.hashicorp.com | Vendor Advisory | |
| https://discuss.hashicorp.com/t/hcsec-2022-24-vaults-tls-cert-auth-method-only-loaded-crl-after-first-request/45483 | Vendor Advisory | |
| https://github.com/advisories/GHSA-9mh8-9j64-443f | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-41316 | ||
| https://security.netapp.com/advisory/ntap-20221201-0001 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-41316 |
Change history (0)
No recorded changes yet.