HashiCorp Nomad vulnerable to non-sensitive metadata exposure
Moderate severity
GitHub Reviewed
Published
Nov 10, 2022
to the GitHub Advisory Database
•
Updated May 31, 2023
Description
Published by the National Vulnerability Database
Nov 10, 2022
Published to the GitHub Advisory Database
Nov 10, 2022
Reviewed
Nov 10, 2022
Last updated
May 31, 2023
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under
nomad/
that belong to other jobs in the same namespace. Fixed in 1.4.2.References