PT-2023-24131 · Hashicorp+1 · Nomad Enterprise+2
Published
2023-07-19
·
Updated
2025-05-26
·
CVE-2023-3300
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Nomad and Nomad Enterprise versions 0.11.0 through 1.5.6
HashiCorp Nomad and Nomad Enterprise version 1.4.1
Description
A vulnerability in the HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy.
Recommendations
For versions 0.11.0 through 1.5.6, update to version 1.5.7 or later to resolve the issue.
For version 1.4.1, update to version 1.4.11 or later to resolve the issue.
Fix
Missing Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Nomad
Nomad Enterprise
Red Os