LOW
Nomad Caller ACL Token's Secret ID is Exposed to Sentinel
Published Jul 19, 2023
3.4
LOWCVSS 3.1
EPSS 0.60%
Description
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
Affected products
-
- Version 1.2.11StatusaffectedConstraints<=1.4.10
- Version 1.2.11StatusaffectedConstraints<=1.5.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| HashiCorp | Nomad Enterprise | unaffected |
|
No data.
No Red Hat product state for this CVE.
github.com/hashicorp/nomad
Go
Introduced 1.2.11 Fixed 1.4.11github.com/hashicorp/nomad
Go
Introduced 1.5.0 Fixed 1.5.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/nomad | 1.2.11 | 1.4.11 |
| Go | github.com/hashicorp/nomad | 1.5.0 | 1.5.7 |
Remediation
No remediation recorded yet.
References (5)
- https://discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271 Vendor Advisory
- https://github.com/advisories/GHSA-9jfx-84v9-2rr2 Advisory
- https://github.com/hashicorp/nomad/issues/17907
- https://nvd.nist.gov/vuln/detail/CVE-2023-3299
- https://pkg.go.dev/vuln/GO-2024-2669
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HashiCorp
Published Jul 19, 2023
Updated Oct 17, 2024
Reserved Jun 16, 2023
Link CVE-2023-3299
CISA Vulnrichment
GHSA-9JFX-84V9-2RR2 Updated Oct 17, 2024