First published: Thu Nov 10 2022(Updated: )
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
Credit: security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | =1.4.0 | |
HashiCorp Nomad | =1.4.0 | |
HashiCorp Nomad | =1.4.1 | |
HashiCorp Nomad | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3867 is a vulnerability in HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1, where event stream subscribers using a token with TTL receive updates until token garbage is collected.
CVE-2022-3867 has a severity level of medium with a score of 4.3.
HashiCorp Nomad and Nomad Enterprise versions 1.4.0 up to 1.4.1 are affected by CVE-2022-3867.
To fix CVE-2022-3867, you need to upgrade to version 1.4.2 of HashiCorp Nomad or Nomad Enterprise.
You can find more information about CVE-2022-3867 at this link: [https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168](https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168)