CVE-2025-4922: Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4922?
CVE-2025-4922 has been identified as a significant vulnerability due to issues with prefix-based ACL policy lookup.
How do I fix CVE-2025-4922?
To fix CVE-2025-4922, upgrade to Nomad Community Edition version 1.10.2 or Nomad Enterprise versions 1.10.2, 1.9.10, or 1.8.14.
What causes CVE-2025-4922?
CVE-2025-4922 is caused by incorrect rule application and shadowing during prefix-based ACL policy lookup.
Which versions of Nomad are affected by CVE-2025-4922?
Nomad versions prior to 1.10.2 are affected by CVE-2025-4922.
Is CVE-2025-4922 a remote code execution vulnerability?
No, CVE-2025-4922 is related to incorrect ACL policymaking rather than remote code execution.