Skip to content
vaultGHSA-9mh8-9j64-443f

HashiCorp Vault's revocation list not respected

Medium5.3CVE-2022-41316 · Published Jul 6, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.11.0, < 1.11.41.11.4
>= 1.10.0, < 1.10.71.10.7
< 1.9.101.9.10
Details and references

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-295
Also known as
BIT-vault-2022-41316, CVE-2022-41316, GO-2023-1897

More vault advisories

All
DateAdvisory
Jul 62023Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4
Aug 12023HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1
Jun 92023Hashicorp Vault vulnerable to Cross-site Scripting
CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3
Sep 152023HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3
Sep 292023Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-5077High7.6fixed in 1.13.0
Mar 302023HashiCorp Vault's PKI mount vulnerable to denial of service
CVE-2023-0665Medium6.5fixed in 1.11.9, 1.12.5, 1.13.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.