First published: Tue Oct 01 2024(Updated: )
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30132 is currently classified as medium due to the potential to expose sensitive information.
To fix CVE-2024-30132, ensure that the HTTP security headers are properly configured in your HCL Nomad server settings.
CVE-2024-30132 affects all versions of HCL Nomad that do not have the HTTP security headers configured.
CVE-2024-30132 facilitates information disclosure attacks due to the missing HTTP security headers.
Yes, a patch or guidance for configuring the necessary security settings is available from HCL support.