CVE-2023-3072Incorrect Privilege Assignment in Hashicorp Nomad

Severity
3.8LOWNVD
CNA4.1
EPSS
0.1%
top 84.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateApr 4

Description

HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NExploitability: 1.2 | Impact: 2.5

Affected Packages4 packages

CVEListV5hashicorp/nomad_enterprise0.7.01.4.10+1
Gogithub.com/hashicorp_nomad0.7.01.4.11+1
CVEListV5hashicorp/nomad0.7.01.4.10+1
NVDhashicorp/nomad0.7.01.4.10+1

🔴Vulnerability Details

5
OSV
ACL security vulnerability in github.com/hashicorp/nomad2024-04-04
GHSA
Nomad ACL Policies without Label are Applied to Unexpected Resources2023-07-20
OSV
CVE-2023-3072: HashiCorp Nomad and Nomad Enterprise 02023-07-20
OSV
Nomad ACL Policies without Label are Applied to Unexpected Resources2023-07-20
CVEList
Nomad ACL Policies without Label are Applied to Unexpected Resources2023-07-19
CVE-2023-3072 — Incorrect Privilege Assignment | cvebase