CVE-2025-3744: Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3744?
CVE-2025-3744 is considered a high severity vulnerability due to its potential to bypass mandatory sentinel policies in Nomad Enterprise.
How do I fix CVE-2025-3744?
To fix CVE-2025-3744, upgrade your Nomad Enterprise to version 1.10.1, 1.9.9, or 1.8.13.
What impact does CVE-2025-3744 have on Nomad Enterprise?
CVE-2025-3744 allows jobs using the policy override option to bypass critical security policies, which can lead to unauthorized access or job execution.
Which versions of Nomad Enterprise are affected by CVE-2025-3744?
CVE-2025-3744 affects Nomad Enterprise versions up to 1.10.1, 1.9.9, and 1.8.13.
Is there a workaround for CVE-2025-3744?
No specific workaround is recommended for CVE-2025-3744; the effective resolution is to upgrade to the patched versions.