NomadGHSA-rpvr-38xv-xvxq
Nomad ACL Policies without Label are Applied to Unexpected Resources
Medium4.1CVE-2023-3072 · Published Jul 20, 2023 · updated Sep 26, 2024
A vulnerability was identified in Nomad, an ACL policy using a block without label may be applied to unexpected resources. This vulnerability, CVE-2023-3072, affects Nomad from 0.7 up to 1.5.6 and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.7.0, < 1.4.11 | 1.4.11 |
| >= 1.5.0, < 1.5.6 | 1.5.6 |
Details and references
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 202023 | Nomad Search API Leaks Information About CSI Plugins | Medium5.3 | 1.4.11+1 more |
| Jul 202023 | Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel | Low3.4 | 1.4.11+1 more |
| Jul 62023 | Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables | Medium5.3 | 1.4.6+1 more |
| Apr 52023 | HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation | High8.8 | 1.5.3 |
| Mar 142023 | Nomad Job Submitter Privilege Escalation Using Workload Identity | High8.8 | 1.5.1 |
| Feb 172023 | Uncontrolled Resource Consumption in Hashicorp Nomad | Medium6.5 | 1.2.16+2 more |