CVE-2023-1299: Nomad Job Submitter Privilege Escalation Using Workload Identity
Published Mar 14, 2023
·Updated
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.
Affected Software
2 affected components
HashiCorp Nomad=1.5.0
HashiCorp Nomad=1.5.0
Event History
Mar 14, 2023
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1299.
2
What is the severity of CVE-2023-1299?
The severity of CVE-2023-1299 is high (8.8).
3
How does CVE-2023-1299 allow an attacker to escalate privileges?
CVE-2023-1299 allows a job submitter to escalate to management-level privileges using workload identity and task API.
4
Which versions of HashiCorp Nomad are affected by CVE-2023-1299?
HashiCorp Nomad 1.5.0 and Nomad Enterprise 1.5.0 are affected by CVE-2023-1299.
5
How can CVE-2023-1299 be fixed?
CVE-2023-1299 can be fixed by applying the patch/update to HashiCorp Nomad and Nomad Enterprise 1.5.1.