Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-hhvx-8755-4cvw: Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables

A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.

ghsa
#vulnerability#git

Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables

Moderate severity GitHub Reviewed Published Jul 6, 2023 to the GitHub Advisory Database • Updated Jul 6, 2023

Related news

CVE-2023-1296: HCSEC-2023-09 - Nomad ACLs Can Not Deny Access to Workload's Own Variables

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.

ghsa: Latest News

GHSA-49cc-xrjf-9qf7: SFTPGo allows administrators to restrict command execution from the EventManager