logo

CVE-2023-1782 github.com/hashicorp/nomad

Package

Manager: go
Name: github.com/hashicorp/nomad
Vulnerable Version: >=1.5.0 <1.5.3

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00357 pctl0.57227

Details

HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

Metadata

Created: 2023-04-05T21:30:24Z
Modified: 2023-04-06T16:59:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-f8r8-h93m-mj77/GHSA-f8r8-h93m-mj77.json
CWE IDs: ["CWE-285", "CWE-862"]
Alternative ID: GHSA-f8r8-h93m-mj77
Finding: F039
Auto approve: 1