CVE-2023-3299 Information

Description

HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0 1.5.7 and 1.4.11.

Reference

https://discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271

Share on: