HashiCorp Nomad
cpe:2.3:a:hashicorp:nomad:*:*:*:*:*:*:*
- >= 1.0.0, <= 1.9.5
- 1.8.9
- 1.7.17
A vulnerability exists in both Nomad Community and Nomad Enterprise event streams that are configured with a wildcard namespace. This vulnerability allows for an ACL policy bypass, enabling unauthorized reads from other namespaces. The issue arises from a flaw in how ACL wildcards are validated, creating a discrepancy that can be exploited when using the event stream endpoint with a wildcard namespace.
Exploiting this vulnerability can lead to unauthorized access to event stream data from other namespaces, bypassing established ACL policies.
Users should upgrade to Nomad Community Edition 1.9.6 or Nomad Enterprise 1.9.6, 1.8.10, or 1.7.18. For guidance on upgrading, refer to the Nomad Upgrade Guides.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.