CVE-2022-41316

MEDIUM

HashiCorp Vault <1.12.0-1.9.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
hashicorp/vault < 1.9.10 (2 CPE variants)
hashicorp/vault 1.11.0 - 1.11.4Go
Published Oct 12, 2022
Tracked Since Feb 18, 2026