CVE-2023-1782 – github.com/hashicorp/nomad
Package
Manager: go
Name: github.com/hashicorp/nomad
Vulnerable Version: >=1.5.0 <1.5.3
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00357 pctl0.57227
Details
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Metadata
Created: 2023-04-05T21:30:24Z
Modified: 2023-04-06T16:59:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-f8r8-h93m-mj77/GHSA-f8r8-h93m-mj77.json
CWE IDs: ["CWE-285", "CWE-862"]
Alternative ID: GHSA-f8r8-h93m-mj77
Finding: F039
Auto approve: 1