HashiCorp Vault's revocation list not respected
Moderate severity
GitHub Reviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Jul 6, 2023
Package
Affected versions
>= 1.11.0, < 1.11.4
>= 1.10.0, < 1.10.7
< 1.9.10
Patched versions
1.11.4
1.10.7
1.9.10
Description
Published by the National Vulnerability Database
Oct 12, 2022
Published to the GitHub Advisory Database
Jul 6, 2023
Reviewed
Jul 6, 2023
Last updated
Jul 6, 2023
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
References