CVE-2025-0937Incorrect Authorization in Nomad

Severity
7.1HIGHNVD
EPSS
0.2%
top 60.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12

Description

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages3 packages

CVEListV5hashicorp/nomad_enterprise1.0.01.9.6
CVEListV5hashicorp/nomad1.0.01.9.6
NVDhashicorp/nomad1.0.01.7.18+3

🔴Vulnerability Details

3
CVEList
Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace2025-02-12
OSV
CVE-2025-0937: Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other nam2025-02-12
GHSA
GHSA-5mx9-vcf9-4hvc: Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other nam2025-02-12

📋Vendor Advisories

1
Red Hat
nomad: Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace2025-02-12
CVE-2025-0937 — Incorrect Authorization in Nomad | cvebase