Skip to content
NomadGHSA-f8r8-h93m-mj77

HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation

High8.8CVE-2023-1782 · Published Apr 5, 2023 · updated Aug 20, 2024

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 1.5.0, < 1.5.31.5.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-285, CWE-862
Also known as
CVE-2023-1782, GO-2023-1707

More Nomad advisories

All Nomad
Advisory
Nomad Search API Leaks Information About CSI Plugins
Medium5.3Jul 20, 2023
Nomad ACL Policies without Label are Applied to Unexpected Resources
Medium4.1Jul 20, 2023
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Low3.4Jul 20, 2023
Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
Medium5.3Jul 6, 2023
Nomad Job Submitter Privilege Escalation Using Workload Identity
High8.8Mar 14, 2023
Uncontrolled Resource Consumption in Hashicorp Nomad
Medium6.5Feb 17, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.