CVE Vulnerabilities

CVE-2023-3072

Incorrect Privilege Assignment

Published: Jul 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.8
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 0.7.0 (including) 1.4.10 (including)
Nomad Hashicorp 1.5.0 (including) 1.5.6 (including)
Nomad Ubuntu bionic *
Nomad Ubuntu trusty *
Nomad Ubuntu xenial *

Potential Mitigations

References