CVE-2025-3744Incorrect Privilege Assignment in Nomad Enterprise

Severity
7.6HIGHNVD
EPSS
0.3%
top 51.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LExploitability: 2.8 | Impact: 4.7

Affected Packages2 packages

CVEListV5hashicorp/nomad_enterprise< 1.10.1
NVDhashicorp/nomad1.9.01.9.9+2

🔴Vulnerability Details

2
CVEList
Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override2025-05-13
GHSA
GHSA-9vr5-w737-m66g: Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies2025-05-13

📋Vendor Advisories

1
Microsoft
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c which allows attackers to cause a denial of service (memory consumption). This vu2022-03-08
CVE-2025-3744 — Incorrect Privilege Assignment | cvebase