CVE-2025-0937: Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0937?
CVE-2025-0937 has been assigned a severity level that may vary based on the specifics of the deployment and potential for exploitation.
How do I fix CVE-2025-0937?
To fix CVE-2025-0937, you should avoid using wildcard namespaces in Nomad event stream configurations and check ACL policies for correct settings.
What versions of HashiCorp Nomad are affected by CVE-2025-0937?
CVE-2025-0937 affects all versions of HashiCorp Nomad that allow wildcard namespace configurations.
What impact does CVE-2025-0937 have on my Nomad deployment?
CVE-2025-0937 may allow unauthorized reads from other namespaces due to improperly configured ACL policies when using wildcard namespaces.
Is there a workaround for CVE-2025-0937?
A potential workaround for CVE-2025-0937 includes manually configuring ACL rules to specify exact namespaces instead of using wildcards.