CVE-2023-1296

Name
CVE-2023-1296
Description
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://discuss.hashicorp.com/t/hcsec-2023-09-nomad-acls-can-not-deny-access-to-workloads-own-variables/51390

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:hashicorp:nomad:1.5.0:*:*:*:-:*:*:* nomad == None == 1.5.0
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* nomad >= 1.4.0 < 1.4.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nomad edge-community 1.5.1-r0 Dermot Bradley <dermot_bradley@yahoo.com> fixed
nomad 3.18-community 1.5.1-r0 None fixed
nomad 3.17-community 1.4.6-r0 Dermot Bradley <dermot_bradley@yahoo.com> fixed