HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HHashicorp Nomad
APPHashicorp1.5.0 – 1.5.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2022-30324CRITICAL9.8PL ✓same product
HashiCorp Nomad: privilege escalation przez podatności go-getter w artifact stanza
CVE-2020-27195CRITICAL9.1PL ✓same product
HashiCorp Nomad — obejście sandboxu klienta przez stanzę template lub artifact
CVE-2020-7956CRITICAL9.8PL ✓same product
Nieprawidłowa walidacja certyfikatów TLS w HashiCorp Nomad — privilege escalation
CVE-2019-12618CRITICAL9.8PL ✓same product
Nieprawidłowa kontrola dostępu w HashiCorp Nomad przez sterownik exec
CVE-2025-4922HIGH8.1same product
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule appli...