PT-2022-24518 · Hashicorp · Nomad+1

Published

2022-11-10

·

Updated

2024-08-21

·

CVE-2022-3867

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.4.0 through 1.4.1
Description The issue affects event stream subscribers using a token with TTL, allowing them to receive updates until token garbage is collected.
Recommendations For versions 1.4.0 through 1.4.1, update to version 1.4.2 to resolve the issue.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2022-3867
GHSA-9FMC-5FQ4-5JWH
GO-2022-1106

Affected Products

Nomad
Nomad Enterprise