5.3

CVE-2022-41316

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

Data is provided by the National Vulnerability Database (NVD)
HashicorpVault SwEdition- Version < 1.9.10
HashicorpVault SwEditionenterprise Version < 1.9.10
HashicorpVault SwEdition- Version >= 1.10.0 < 1.10.7
HashicorpVault SwEditionenterprise Version >= 1.10.0 < 1.10.7
HashicorpVault SwEdition- Version >= 1.11.0 < 1.11.4
HashicorpVault SwEditionenterprise Version >= 1.11.0 < 1.11.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.299
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.