MEDIUM4.1
GHSA-rpvr-38xv-xvxq
Nomad ACL Policies without Label are Applied to Unexpected Resources
Quick fix
GHSA-rpvr-38xv-xvxq — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad@v1.4.11Details
A vulnerability was identified in Nomad, an ACL policy using a block without label may be applied to unexpected resources. This vulnerability, CVE-2023-3072, affects Nomad from 0.7 up to 1.5.6 and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad
Introduced in:
0.7.0Fixed in: 1.4.11Fix
go get github.com/hashicorp/nomad@v1.4.11Go/github.com/hashicorp/nomad
Introduced in:
1.5.0Fixed in: 1.5.6Fix
go get github.com/hashicorp/nomad@v1.5.6