Headline
GHSA-hhvx-8755-4cvw: Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.
Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
Moderate severity GitHub Reviewed Published Jul 6, 2023 to the GitHub Advisory Database • Updated Jul 6, 2023
Related news
CVE-2023-1296: HCSEC-2023-09 - Nomad ACLs Can Not Deny Access to Workload's Own Variables
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.