Insecure digital certificates In github.com/hashicorp/vault
Description
HashiCorp Vault's revocation list not respected HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.11.4, 1.10.7, 1.9.10 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.