NomadGHSA-f8r8-h93m-mj77
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High8.8CVE-2023-1782 · Published Apr 5, 2023 · updated Aug 20, 2024
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 1.5.0, < 1.5.3 | 1.5.3 |
Details and references
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 202023 | Nomad Search API Leaks Information About CSI Plugins | Medium5.3 | 1.4.11+1 more |
| Jul 202023 | Nomad ACL Policies without Label are Applied to Unexpected Resources | Medium4.1 | 1.4.11+1 more |
| Jul 202023 | Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel | Low3.4 | 1.4.11+1 more |
| Jul 62023 | Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables | Medium5.3 | 1.4.6+1 more |
| Mar 142023 | Nomad Job Submitter Privilege Escalation Using Workload Identity | High8.8 | 1.5.1 |
| Feb 172023 | Uncontrolled Resource Consumption in Hashicorp Nomad | Medium6.5 | 1.2.16+2 more |