PT-2023-24131 · Hashicorp+1 · Nomad Enterprise+2

Published

2023-07-19

·

Updated

2025-05-26

·

CVE-2023-3300

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 0.11.0 through 1.5.6 HashiCorp Nomad and Nomad Enterprise version 1.4.1
Description A vulnerability in the HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy.
Recommendations For versions 0.11.0 through 1.5.6, update to version 1.5.7 or later to resolve the issue. For version 1.4.1, update to version 1.4.11 or later to resolve the issue.

Fix

Missing Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-06167
CVE-2023-3300
GHSA-V5FM-HR72-27HX
GO-2024-2671

Affected Products

Hashicorp Nomad
Nomad Enterprise
Red Os