First published: Thu Apr 22 2021(Updated: )
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=1.5.1<1.5.8 | |
HashiCorp Vault | >=1.5.1<1.5.8 | |
HashiCorp Vault | >=1.6.0<1.6.4 | |
HashiCorp Vault | >=1.6.0<1.6.4 | |
HashiCorp Vault | >=1.7.0<1.7.1 | |
HashiCorp Vault | >=1.7.0<1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29653 is a vulnerability in HashiCorp Vault and Vault Enterprise 1.5.1 and newer where revoked but unexpired certificates may be excluded from the certificate revocation list (CRL).
CVE-2021-29653 has a severity score of 7.5 (high).
CVE-2021-29653 affects HashiCorp Vault and Vault Enterprise versions 1.5.1 to 1.5.8, 1.6.0 to 1.6.4, and 1.7.0 to 1.7.1.
Yes, the vulnerability has been fixed in HashiCorp Vault versions 1.5.8, 1.6.4, and 1.7.1.
More information about CVE-2021-29653 can be found at the following link: [https://discuss.hashicorp.com/t/hcsec-2021-09-vault-s-pki-engine-crl-may-exclude-revoked-but-unexpired-certificates-after-tidy/23461/2](https://discuss.hashicorp.com/t/hcsec-2021-09-vault-s-pki-engine-crl-may-exclude-revoked-but-unexpired-certificates-after-tidy/23461/2)