First published: Tue Mar 14 2023(Updated: )
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.
Credit: security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | =1.5.0 | |
HashiCorp Nomad | =1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1299.
The severity of CVE-2023-1299 is high (8.8).
CVE-2023-1299 allows a job submitter to escalate to management-level privileges using workload identity and task API.
HashiCorp Nomad 1.5.0 and Nomad Enterprise 1.5.0 are affected by CVE-2023-1299.
CVE-2023-1299 can be fixed by applying the patch/update to HashiCorp Nomad and Nomad Enterprise 1.5.1.