Insecure digital certificates In github.com/hashicorp/nomad
Description
Improper Certificate Validation in HashiCorp Nomad HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.10.3 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.