Lucene search

K
cvelistMitreCVELIST:CVE-2022-41316
HistoryOct 12, 2022 - 12:00 a.m.

CVE-2022-41316

2022-10-1200:00:00
mitre
www.cve.org
1
hashicorp vault
tls certificate
crl
revocation lists

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.5%

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role’s CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.5%