Back

MEDIUM

vault: insufficient certificate revocation list checking

Published Oct 12, 2022

Description

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 12, 2022
Updated May 15, 2025
Reserved Sep 23, 2022
CISA Vulnrichment
Updated May 15, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 12, 2022
GHSA-9MH8-9J64-443F