HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vault | Hashicorp | 1.5.1 (including) | 1.5.8 (excluding) |
Vault | Hashicorp | 1.6.0 (including) | 1.6.4 (excluding) |
Vault | Hashicorp | 1.7.0 (including) | 1.7.1 (excluding) |