CVE-2023-1782: Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation
Published Apr 5, 2023
·Updated
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Affected Software
2 affected components
HashiCorp Nomad>=1.5.0<=1.5.2
HashiCorp Nomad>=1.5.0<=1.5.2
Event History
Apr 5, 2023
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1782.
2
What is the severity of CVE-2023-1782?
The severity of CVE-2023-1782 is critical with a severity value of 9.8.
3
Which versions of HashiCorp Nomad and Nomad Enterprise are affected?
Versions 1.5.0 up to 1.5.2 of HashiCorp Nomad and Nomad Enterprise are affected.
4
How can unauthenticated users bypass ACL authorizations in affected versions of HashiCorp Nomad and Nomad Enterprise?
Unauthenticated users can bypass intended ACL authorizations for clusters where mTLS is not enabled.
5
How can I fix CVE-2023-1782?
Update to version 1.5.3 of HashiCorp Nomad or Nomad Enterprise to fix the vulnerability.