PT-2021-18385 · Hashicorp · Vault Enterprise+1

Published

2021-04-22

·

Updated

2024-03-06

·

CVE-2021-29653

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions prior to 1.5.8 HashiCorp Vault and Vault Enterprise versions prior to 1.6.4 HashiCorp Vault and Vault Enterprise versions prior to 1.7.1
Description The issue concerns the exclusion of revoked but unexpired certificates from the Certificate Revocation List (CRL) under certain circumstances.
Recommendations For versions prior to 1.5.8, update to version 1.5.8 or newer. For versions prior to 1.6.4, update to version 1.6.4 or newer. For versions prior to 1.7.1, update to version 1.7.1 or newer.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-VAULT-2021-29653
CVE-2021-29653

Affected Products

Hashicorp Vault
Vault Enterprise