nomadGHSA-hhvx-8755-4cvw
Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
Medium5.3CVE-2023-1296 · Published Jul 6, 2023 · updated Aug 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 1.4.0, < 1.4.6 | 1.4.6 |
| >= 1.5.0, < 1.5.1 | 1.5.1 |
Details and references
A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2023-1296, GO-2023-1899
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 202023 | Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel CVE-2023-3299Low3.4fixed in 1.4.11, 1.5.7 | Low3.4 | 1.4.11, 1.5.7 |
| Jul 202023 | Nomad ACL Policies without Label are Applied to Unexpected Resources CVE-2023-3072Medium4.1fixed in 1.4.11, 1.5.6 | Medium4.1 | 1.4.11, 1.5.6 |
| Jul 202023 | Nomad Search API Leaks Information About CSI Plugins CVE-2023-3300Medium5.3fixed in 1.4.11, 1.5.7 | Medium5.3 | 1.4.11, 1.5.7 |
| Apr 52023 | HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation CVE-2023-1782High8.8fixed in 1.5.3 | High8.8 | 1.5.3 |
| Mar 142023 | Nomad Job Submitter Privilege Escalation Using Workload Identity CVE-2023-1299High8.8fixed in 1.5.1 | High8.8 | 1.5.1 |
| Feb 172023 | Uncontrolled Resource Consumption in Hashicorp Nomad CVE-2023-0821Medium6.5fixed in 1.2.16, 1.3.9, 1.4.4 | Medium6.5 | 1.2.16, 1.3.9, 1.4.4 |