CVE-2023-3300: Nomad Search API Leaks Information About CSI Plugins
A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Other sources
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.5.7 - Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.4.11 - Upgrade
Upgrade
hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.6.0 - Upgrade
Upgrade
hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.5.7 - Upgrade
Upgrade
hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.4.1
Event History
Frequently Asked Questions
What is CVE-2023-3300?
CVE-2023-3300 is a vulnerability in HashiCorp Nomad and Nomad Enterprise versions 0.11.0 up to 1.5.6 and 1.4.1, where the HTTP search API can reveal the names of available CSI plugins to unauthenticated users or users without the plugin:read policy.
How does the CVE-2023-3300 vulnerability affect HashiCorp Nomad?
The CVE-2023-3300 vulnerability affects HashiCorp Nomad versions 0.11.0 up to 1.5.6 and 1.4.1.
What is the severity of CVE-2023-3300?
CVE-2023-3300 has a severity rating of 5.3 (Medium).
How can I fix CVE-2023-3300 in HashiCorp Nomad?
To fix CVE-2023-3300 in HashiCorp Nomad, update to version 1.6.0, 1.5.7, or 1.4.1.
Where can I find more information about CVE-2023-3300?
You can find more information about CVE-2023-3300 at the following reference: [https://discuss.hashicorp.com/t/hcsec-2023-22-nomad-search-api-leaks-information-about-csi-plugins/56272](https://discuss.hashicorp.com/t/hcsec-2023-22-nomad-search-api-leaks-information-about-csi-plugins/56272)