Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: HashiCorp
Published: 2024-04-04T17:55:20.192Z
Updated: 2024-04-04T17:55:20.192Z
Reserved: 2024-03-19T17:34:27.401Z
Link: CVE-2024-2660
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-04-04T18:15:14.783
Modified: 2024-06-10T17:16:25.443
Link: CVE-2024-2660
JSON object: View
Redhat Information
No data.
CWE