HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nomad | Hashicorp | 1.4.0 (including) | 1.4.0 (including) |
Nomad | Hashicorp | 1.4.1 (including) | 1.4.1 (including) |
Nomad | Ubuntu | bionic | * |
Nomad | Ubuntu | trusty | * |
Nomad | Ubuntu | upstream | * |
Nomad | Ubuntu | xenial | * |