Improper Certificate Validation in Vault Enterprise and Vault - CVE-2021-29653

 

Improper Certificate Validation in Vault Enterprise and Vault - CVE-2021-29653

Published: April 21, 2021 / Updated: April 17, 2026


Vulnerability identifier: #VU126404
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29653
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass certificate revocation checks.

The vulnerability exists due to improper certificate revocation handling in the PKI Secrets Engine CRL generation logic when processing a tidy operation with tidy_revoked_certs enabled. A remote user can use a revoked but unexpired certificate to bypass certificate revocation checks.

Exploitation requires use of the PKI revocation mechanism and enforcement of the generated certificate revocation list, and only occurs when the tidy_revoked_certs setting is enabled.


Affected software

Vault Enterprise
Vault

How to mitigate CVE-2021-29653

Install security update from vendor's website.

Vault Enterprise - addressed in versions 1.5.8, 1.6.4, 1.7.1
Vault - addressed in versions 1.5.8, 1.6.4, 1.7.1

External References

Related Security Bulletins