CVE Vulnerabilities

CVE-2022-3867

Insufficient Session Expiration

Published: Nov 10, 2022 | Modified: Nov 15, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 1.4.0 (including) 1.4.0 (including)
Nomad Hashicorp 1.4.1 (including) 1.4.1 (including)
Nomad Ubuntu bionic *
Nomad Ubuntu trusty *
Nomad Ubuntu upstream *
Nomad Ubuntu xenial *

Potential Mitigations

References