VDB
Sign up
MEDIUM4.1

GHSA-rpvr-38xv-xvxq

Nomad ACL Policies without Label are Applied to Unexpected Resources

Quick fix

GHSA-rpvr-38xv-xvxq — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.

go get github.com/hashicorp/nomad@v1.4.11

Details

A vulnerability was identified in Nomad, an ACL policy using a block without label may be applied to unexpected resources. This vulnerability, CVE-2023-3072, affects Nomad from 0.7 up to 1.5.6 and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/nomad
Introduced in: 0.7.0Fixed in: 1.4.11
Fixgo get github.com/hashicorp/nomad@v1.4.11
Go/github.com/hashicorp/nomad
Introduced in: 1.5.0Fixed in: 1.5.6
Fixgo get github.com/hashicorp/nomad@v1.5.6

References