PT-2023-17240 · Hashicorp · Nomad+1
Published
2023-04-05
·
Updated
2024-08-20
·
CVE-2023-1782
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 through 1.5.2
Description
The issue allows unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This can lead to unauthorized access and potential privilege escalation. The problem is fixed in version 1.5.3.
Recommendations
For versions 1.5.0 through 1.5.2, update to version 1.5.3 to resolve the issue.
As a temporary workaround, consider enabling mTLS for clusters to minimize the risk of exploitation.
Fix
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nomad
Nomad Enterprise