CVE-2022-3866: Nomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
Other sources
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.4.2 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Frequently Asked Questions
What is CVE-2022-3866?
CVE-2022-3866 is a vulnerability in HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 that allows a workload identity token to list non-sensitive metadata for paths under `nomad/` that belong to other jobs in the same namespace.
How severe is CVE-2022-3866?
CVE-2022-3866 has a severity level of medium.
How can I fix CVE-2022-3866?
To fix CVE-2022-3866, update your HashiCorp Nomad or Nomad Enterprise installation to version 1.4.2.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-3866?
The CWE ID for CVE-2022-3866 is 668.
Where can I find more information about CVE-2022-3866?
You can find more information about CVE-2022-3866 on the NIST National Vulnerability Database, HashiCorp discussion forum, and the HashiCorp Nomad GitHub repository.