PT-2025-10607 · Hashicorp+1 · Nomad Enterprise+2

Published

2025-03-10

·

Updated

2025-12-18

·

CVE-2025-1296

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nomad Community and Nomad Enterprise versions prior to 1.9.7 Nomad Enterprise versions prior to 1.8.11 Nomad Enterprise versions prior to 1.7.19
Description The issue concerns unintentional exposure of the workload identity token and client secret token in audit logs.
Recommendations For Nomad Community and Nomad Enterprise versions prior to 1.9.7, update to version 1.9.7. For Nomad Enterprise versions prior to 1.8.11, update to version 1.8.11. For Nomad Enterprise versions prior to 1.7.19, update to version 1.7.19.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2025-06561
CVE-2025-1296
GHSA-C3Q9-Q986-VRWH
GO-2025-3510
OPENSUSE-SU-2025:14893-1

Affected Products

Nomad Community
Nomad Enterprise
Red Os