Sensitive information sent insecurely In github.com/hashicorp/nomad

Description

HashiCorp Nomad vulnerable to non-sensitive metadata exposure HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-K239Q – Vulnerability | Fluid Attacks Database