nomadGHSA-hr68-hvgv-xxqf
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Medium6.5CVE-2024-12678 · Published Dec 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.9.4 | 1.9.4 |
Details and references
Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- CVE-2024-12678, GO-2024-3354
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability CVE-2024-10975Medium7.7no fix yet | Medium7.7 | No fix yet |
| Mar 102025 | Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs CVE-2025-1296Medium6.5no fix yet | Medium6.5 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking CVE-2024-7625Medium5.8fixed in 1.6.14, 1.7.11, 1.8.3 | Medium5.8 | 1.6.14, 1.7.11, 1.8.3 |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration CVE-2024-6717High7.7fixed in 1.8.2 | High7.7 | 1.8.2 |
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability CVE-2025-4922High8.1fixed in 1.10.2 | High8.1 | 1.10.2 |
| Feb 82024 | HashiCorp Nomad vulnerable to symlink attacks CVE-2024-1329High7.7fixed in 1.5.14, 1.6.7, 1.7.4 | High7.7 | 1.5.14, 1.6.7, 1.7.4 |