VDB
Sign up
MEDIUM5.3

GHSA-v5fm-hr72-27hx

Nomad Search API Leaks Information About CSI Plugins

Quick fix

GHSA-v5fm-hr72-27hx — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.

go get github.com/hashicorp/nomad@v1.4.11

Details

A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/nomad
Introduced in: 0.11.0Fixed in: 1.4.11
Fixgo get github.com/hashicorp/nomad@v1.4.11
Go/github.com/hashicorp/nomad
Introduced in: 1.5.0Fixed in: 1.5.7
Fixgo get github.com/hashicorp/nomad@v1.5.7

References