CVE-2023-1296: Nomad ACLs Can Not Deny Access to Workload's Own Variables
Published Mar 14, 2023
·Updated
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
Affected Software
4 affected components
HashiCorp Nomad>=1.4.0<1.4.6
HashiCorp Nomad>=1.4.0<1.4.6
HashiCorp Nomad=1.5.0
HashiCorp Nomad=1.5.0
Event History
Mar 14, 2023
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1296.
2
What is the severity of CVE-2023-1296?
The severity of CVE-2023-1296 is medium with a CVSS score of 5.3.
3
Which software versions are affected by CVE-2023-1296?
HashiCorp Nomad and Nomad Enterprise versions 1.4.0 up to 1.5.0 are affected by CVE-2023-1296.
4
How can I fix CVE-2023-1296?
To fix CVE-2023-1296, update to HashiCorp Nomad version 1.4.6 or 1.5.1.
5
Where can I find more information about CVE-2023-1296?
You can find more information about CVE-2023-1296 on the official HashiCorp discussion forum: [https://discuss.hashicorp.com/t/hcsec-2023-09-nomad-acls-can-not-deny-access-to-workloads-own-variables/51390](https://discuss.hashicorp.com/t/hcsec-2023-09-nomad-acls-can-not-deny-access-to-workloads-own-variables/51390).