CVE-2023-3072: Nomad ACL Policies without Label are Applied to Unexpected Resources
A vulnerability was identified in Nomad, an ACL policy using a block without label may be applied to unexpected resources. This vulnerability, CVE-2023-3072, affects Nomad from 0.7 up to 1.5.6 and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Other sources
HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.5.6 - Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.4.11 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.6.0 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.5.7 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.4.11
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3072.
What is the affected software?
The affected software is HashiCorp Nomad and Nomad Enterprise versions 0.7.0 up to 1.5.6 and 1.4.10.
What is the severity of CVE-2023-3072?
The severity of CVE-2023-3072 is medium (3.8).
How can I fix CVE-2023-3072?
You can fix CVE-2023-3072 by upgrading to version 1.6.0, 1.5.7, or 1.4.11 of HashiCorp Nomad or Nomad Enterprise.
Where can I find more information about CVE-2023-3072?
You can find more information about CVE-2023-3072 at the following link: [CVE-2023-3072](https://discuss.hashicorp.com/t/hcsec-2023-20-nomad-acl-policies-without-label-are-applied-to-unexpected-resources/56270).