VDB
Sign up
MEDIUM5.3

GHSA-9mh8-9j64-443f

HashiCorp Vault's revocation list not respected

Quick fix

GHSA-9mh8-9j64-443f — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.11.4

Details

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 1.11.0Fixed in: 1.11.4
Fixgo get github.com/hashicorp/vault@v1.11.4
Go/github.com/hashicorp/vault
Introduced in: 1.10.0Fixed in: 1.10.7
Fixgo get github.com/hashicorp/vault@v1.10.7
Go/github.com/hashicorp/vault
Introduced in: 0Fixed in: 1.9.10
Fixgo get github.com/hashicorp/vault@v1.9.10

References