CVE-2022-3867: Nomad Event Stream Subscriber Using a Token with TTL Receives Updates Until Garbage Collected
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Frequently Asked Questions
What is CVE-2022-3867?
CVE-2022-3867 is a vulnerability in HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1, where event stream subscribers using a token with TTL receive updates until token garbage is collected.
How severe is CVE-2022-3867?
CVE-2022-3867 has a severity level of medium with a score of 4.3.
Which software versions are affected by CVE-2022-3867?
HashiCorp Nomad and Nomad Enterprise versions 1.4.0 up to 1.4.1 are affected by CVE-2022-3867.
How can I fix CVE-2022-3867?
To fix CVE-2022-3867, you need to upgrade to version 1.4.2 of HashiCorp Nomad or Nomad Enterprise.
Where can I find more information about CVE-2022-3867?
You can find more information about CVE-2022-3867 at this link: [https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168](https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168)