CRITICAL🇵🇱 Wersja polska

CVE-2023-1782

CVSS 9.9v3.1pub. 2023-04-05upd. 2024-11-21

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Hashicorp Nomad

    APP
    Hashicorp
    1.5.0 – 1.5.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-30324CRITICAL9.8PL ✓same product

HashiCorp Nomad: privilege escalation przez podatności go-getter w artifact stanza

CVE-2020-27195CRITICAL9.1PL ✓same product

HashiCorp Nomad — obejście sandboxu klienta przez stanzę template lub artifact

CVE-2020-7956CRITICAL9.8PL ✓same product

Nieprawidłowa walidacja certyfikatów TLS w HashiCorp Nomad — privilege escalation

CVE-2019-12618CRITICAL9.8PL ✓same product

Nieprawidłowa kontrola dostępu w HashiCorp Nomad przez sterownik exec

CVE-2025-4922HIGH8.1same product

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule appli...