vaultGHSA-9mh8-9j64-443f
HashiCorp Vault's revocation list not respected
Medium5.3CVE-2022-41316 · Published Jul 6, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.11.0, < 1.11.4 | 1.11.4 |
| >= 1.10.0, < 1.10.7 | 1.10.7 | |
| < 1.9.10 | 1.9.10 |
Details and references
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-295
- Also known as
- BIT-vault-2022-41316, CVE-2022-41316, GO-2023-1897
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4 | High8.1 | 1.10.11, 1.11.8, 1.12.4 |
| Aug 12023 | HashiCorp Vault and Vault Enterprise vulnerable to user enumeration CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1 | Medium5.3 | 1.13.5, 1.14.1 |
| Jun 92023 | Hashicorp Vault vulnerable to Cross-site Scripting CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3 | Medium4.3 | 1.11.11, 1.12.7, 1.13.3 |
| Sep 152023 | HashiCorp Vault Improper Input Validation vulnerability CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3 | Medium6.8 | 1.12.11, 1.13.7, 1.14.3 |
| Sep 292023 | Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability CVE-2023-5077High7.6fixed in 1.13.0 | High7.6 | 1.13.0 |
| Mar 302023 | HashiCorp Vault's PKI mount vulnerable to denial of service CVE-2023-0665Medium6.5fixed in 1.11.9, 1.12.5, 1.13.1 | Medium6.5 | 1.11.9, 1.12.5, 1.13.1 |