Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
Moderate severity
GitHub Reviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Jul 6, 2023
Package
Affected versions
>= 1.4.0, < 1.4.6
= 1.5.0
Patched versions
1.4.6
1.5.1
Description
Published by the National Vulnerability Database
Mar 14, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Reviewed
Jul 6, 2023
Last updated
Jul 6, 2023
A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.
References