—
GO-2022-1106
HashiCorp Nomad vulnerable to Insufficient Session Expiration in github.com/hashicorp/nomad
Quick fix
GO-2022-1106 — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad@v1.4.2Details
HashiCorp Nomad vulnerable to Insufficient Session Expiration in github.com/hashicorp/nomad
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad
Introduced in:
1.4.0Fixed in: 1.4.2Fix
go get github.com/hashicorp/nomad@v1.4.2References
- https://github.com/advisories/GHSA-9fmc-5fq4-5jwh[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-3867[ADVISORY]
- https://github.com/hashicorp/nomad/commit/dd6a4634a9652197fe4182e830f9a737d0ae1216[FIX]
- https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168[WEB]