Skip to content
NomadGHSA-9fmc-5fq4-5jwh

HashiCorp Nomad vulnerable to Insufficient Session Expiration

Low2.7CVE-2022-3867 · Published Nov 10, 2022 · updated Aug 21, 2024

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 1.4.0, < 1.4.21.4.2
Details and references

More Nomad advisories

All Nomad
Advisory
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High8.8Apr 5, 2023
Nomad Job Submitter Privilege Escalation Using Workload Identity
High8.8Mar 14, 2023
Uncontrolled Resource Consumption in Hashicorp Nomad
Medium6.5Feb 17, 2023
HashiCorp Nomad vulnerable to non-sensitive metadata exposure
Medium5.0Nov 10, 2022
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
Medium6.5Oct 12, 2022
Privilege escalation in Hashicorp Nomad
Critical9.8Jun 3, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.