CVE-2022-41316
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
- Affected products
- Hashicorp Vault, Red Os, Vault Enterprise
- Hashicorp Vault
- < 1.9.10, 1.10.7, 1.11.4
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-295
- NVD status
- Modified
- Published
- 2022-10-12
CVE-2022-41316 at NVD
No indexed exploits for CVE-2022-41316 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-41316 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.