CVE-2022-41316

CVE-2022-41316

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role’s CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

Source: CVE-2022-41316

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다