MEDIUM5.3
GHSA-9mh8-9j64-443f
HashiCorp Vault's revocation list not respected
Quick fix
GHSA-9mh8-9j64-443f — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.11.4Details
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
1.11.0Fixed in: 1.11.4Fix
go get github.com/hashicorp/vault@v1.11.4Go/github.com/hashicorp/vault
Introduced in:
1.10.0Fixed in: 1.10.7Fix
go get github.com/hashicorp/vault@v1.10.7Go/github.com/hashicorp/vault
Introduced in:
0Fixed in: 1.9.10Fix
go get github.com/hashicorp/vault@v1.9.10References
- https://nvd.nist.gov/vuln/detail/CVE-2022-41316[ADVISORY]
- https://discuss.hashicorp.com[WEB]
- https://discuss.hashicorp.com/t/hcsec-2022-24-vaults-tls-cert-auth-method-only-loaded-crl-after-first-request/45483[WEB]
- https://github.com/hashicorp/vault[PACKAGE]
- https://security.netapp.com/advisory/ntap-20221201-0001[WEB]