Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HashiCorp Vault 信任管理问题漏洞
Vulnerability Description
HashiCorp Vault是美国HashiCorp公司的一款私钥访问管理工具。 HashiCorp Vault and Vault Enterprise存在安全漏洞,该漏洞源于其TLS证书认证方法最初没有在启动时将角色的CA颁发的可选配置的CRL加载到内存中,导致如果尚未检索到CRL,则不检查吊销列表。
CVSS Information
N/A
Vulnerability Type
N/A