MEDIUM5.3
GHSA-v5fm-hr72-27hx
Nomad Search API Leaks Information About CSI Plugins
Quick fix
GHSA-v5fm-hr72-27hx — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad@v1.4.11Details
A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad
Introduced in:
0.11.0Fixed in: 1.4.11Fix
go get github.com/hashicorp/nomad@v1.4.11Go/github.com/hashicorp/nomad
Introduced in:
1.5.0Fixed in: 1.5.7Fix
go get github.com/hashicorp/nomad@v1.5.7References
- https://nvd.nist.gov/vuln/detail/CVE-2023-3300[ADVISORY]
- https://github.com/hashicorp/nomad/commit/a8789d3872bbf1b1f420f28b0f7ad8532a41d5e3[WEB]
- https://discuss.hashicorp.com/t/hcsec-2023-22-nomad-search-api-leaks-information-about-csi-plugins/56272[WEB]
- https://github.com/hashicorp/nomad[PACKAGE]
- https://pkg.go.dev/vuln/GO-2024-2671[WEB]