CVE-2022-41316

EUVD-2023-2017
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
hashicorpvault
𝑥
< 1.9.10
hashicorpvault
𝑥
< 1.9.10
hashicorpvault
1.10.0 ≤
𝑥
< 1.10.7
hashicorpvault
1.10.0 ≤
𝑥
< 1.10.7
hashicorpvault
1.11.0 ≤
𝑥
< 1.11.4
hashicorpvault
1.11.0 ≤
𝑥
< 1.11.4
𝑥
= Vulnerable software versions