Insecure session management In github.com/hashicorp/nomad
Description
Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.9.7 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.