First published: Wed Jul 19 2023(Updated: )
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
Credit: security@hashicorp.com security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | >=1.2.11<=1.4.10 | |
HashiCorp Nomad | >=1.2.11<=1.4.10 | |
HashiCorp Nomad | >=1.5.0<=1.5.6 | |
HashiCorp Nomad | >=1.5.0<=1.5.6 | |
go/github.com/hashicorp/nomad | >=1.5.0<1.5.7 | 1.5.7 |
go/github.com/hashicorp/nomad | >=1.2.11<1.4.11 | 1.4.11 |
>=1.2.11<=1.4.10 | ||
>=1.2.11<=1.4.10 | ||
>=1.5.0<=1.5.6 | ||
>=1.5.0<=1.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3299 is low.
CVE-2023-3299 is about an issue in HashiCorp Nomad Enterprise where ACL policies using a block without a label generate unexpected results.
HashiCorp Nomad Enterprise versions 1.2.11 up to 1.5.6 and 1.4.10 are affected by CVE-2023-3299.
CVE-2023-3299 is fixed in HashiCorp Nomad Enterprise versions 1.6.0, 1.5.7, and 1.4.11. It is recommended to update to one of these versions.
You can find more information about CVE-2023-3299 at the following link: [CVE-2023-3299](https://discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271)