NomadGHSA-c3q9-q986-vrwh
Nomad: secrets in logs
Medium6.5CVE-2025-1296 · Published Mar 10, 2025 · updated Mar 14, 2025
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | <= 1.9.6 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- CVE-2025-1296, GO-2025-3510
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | High8.1 | 1.10.2 |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration | High7.7 | 1.8.2 |
| Feb 82024 | HashiCorp Nomad vulnerable to symlink attacks | High7.7 | 1.5.14+2 more |