Skip to content
nomadGHSA-hr68-hvgv-xxqf

Hashicorp Nomad Incorrect Privilege Assignment vulnerability

Medium6.5CVE-2024-12678 · Published Dec 20, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.9.41.9.4
Details and references

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
CVE-2024-12678, GO-2024-3354

More nomad advisories

All
DateAdvisory
Nov 72024Hashicorp Nomad Incorrect Authorization vulnerability
CVE-2024-10975Medium7.7no fix yet
Mar 102025Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
CVE-2025-1296Medium6.5no fix yet
Aug 152024Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
CVE-2024-7625Medium5.8fixed in 1.6.14, 1.7.11, 1.8.3
Jul 232024HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
CVE-2024-6717High7.7fixed in 1.8.2
Jun 112025Hashicorp Nomad Incorrect Privilege Assignment vulnerability
CVE-2025-4922High8.1fixed in 1.10.2
Feb 82024HashiCorp Nomad vulnerable to symlink attacks
CVE-2024-1329High7.7fixed in 1.5.14, 1.6.7, 1.7.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.