LOW3.4
GHSA-9jfx-84v9-2rr2
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Quick fix
GHSA-9jfx-84v9-2rr2 — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad@v1.4.11Details
A vulnerability was identified in Nomad such that the API caller’s ACL token secret ID is exposed to Sentinel policies. This vulnerability, CVE-2023-3299, affects Nomad from 1.2.11 up to 1.5.6, and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad
Introduced in:
1.2.11Fixed in: 1.4.11Fix
go get github.com/hashicorp/nomad@v1.4.11Go/github.com/hashicorp/nomad
Introduced in:
1.5.0Fixed in: 1.5.7Fix
go get github.com/hashicorp/nomad@v1.5.7References
- https://nvd.nist.gov/vuln/detail/CVE-2023-3299[ADVISORY]
- https://github.com/hashicorp/nomad/issues/17907[WEB]
- https://discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271[WEB]
- https://github.com/hashicorp/nomad[PACKAGE]
- https://pkg.go.dev/vuln/GO-2024-2669[WEB]